High severity7.5NVD Advisory· Published May 20, 2024· Updated Jun 17, 2026
CVE-2024-3761
CVE-2024-3761
Description
In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at packages/backend/src/api/v1/datasets is vulnerable to unauthorized dataset deletion due to missing authorization and authentication mechanisms. This vulnerability allows any user, even those without a valid token, to delete a dataset by sending a DELETE request to the endpoint. The issue was fixed in version 1.2.8. The impact of this vulnerability is significant as it permits unauthorized users to delete datasets, potentially leading to data loss or disruption of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/lunary-ai/lunary/commit/14078c1d2b8766075bf655f187ece24c7a787776nvdPatch
- huntr.com/bounties/e95fb0a0-e54a-4da8-a33d-ba858d0cec55nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.