VYPR
Critical severity9.8NVD Advisory· Published Nov 1, 2024· Updated Jun 17, 2026

CVE-2024-7456

CVE-2024-7456

Description

A SQL injection vulnerability exists in the /api/v1/external-users route of lunary-ai/lunary version v1.4.2. The order by clause of the SQL query uses sql.unsafe without prior sanitization, allowing for SQL injection. The orderByClause variable is constructed without server-side validation or sanitization, enabling an attacker to execute arbitrary SQL commands. Successful exploitation can lead to complete data loss, modification, or corruption.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:lunary:lunary:1.4.2:*:*:*:*:*:*:*
  • Lunary AI/Lunaryllm-fuzzy2 versions
    =v1.4.2+ 1 more
    • (no CPE)range: =v1.4.2
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.