High severity7.3NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-8765
CVE-2024-8765
Description
In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fanvdPatch
- huntr.com/bounties/4908cfcf-607a-412a-9635-966cbb08bb49nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.