High severity8.1NVD Advisory· Published May 20, 2024· Updated Jun 17, 2026
CVE-2024-4151
CVE-2024-4151
Description
An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to insufficient access control checks in the handling of PATCH and GET requests for template versions. This vulnerability allows unauthorized users to manipulate or access sensitive project data, potentially leading to data integrity and confidentiality issues.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- huntr.com/bounties/4acfef85-dedf-43bd-8438-0d8aaa4ffa01nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/lunary-ai/lunary/commit/ddfd497afd017a6946c582a1a806687fdac888bfnvd
News mentions
0No linked articles in our index yet.