High severity8.1NVD Advisory· Published Nov 14, 2024· Updated Jun 17, 2026
CVE-2024-3501
CVE-2024-3501
Description
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of GET /v1/users/me and GET /v1/users/me/org API endpoints. These tokens, intended for sensitive operations such as password resets or account verification, are exposed to unauthorized actors, potentially allowing them to perform actions on behalf of the user. This issue was addressed in version 1.2.6, where the exposure of single-use tokens in user-facing queries was mitigated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/lunary-ai/lunary/commit/17e95f6c99c7d5ac4ee5451c5857b97a12892c74nvdPatch
- huntr.com/bounties/8fdfdb9d-10bd-4f00-8004-d5baabc20c6envdIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.