VYPR
High severity7.3NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-8765

CVE-2024-8765

Description

In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
    Range: <1.4.23
  • Lunary AI/Lunaryllm-fuzzy2 versions
    git afc5df4+ 1 more
    • (no CPE)range: git afc5df4
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.