Critical severity9.1NVD Advisory· Published Apr 10, 2024· Updated Jun 17, 2026
CVE-2024-1741
CVE-2024-1741
Description
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/lunary-ai/lunary/commit/d8e2e73efd53ab4e92cf47bbf4b639a9f08853d2nvdPatch
- huntr.com/bounties/671bd040-1cc5-4227-8182-5904e9c5ed3bnvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.