VYPR
Vendor

Lunary

Products
1
CVEs
36
Across products
36
Status
Private

Products

1

Recent CVEs

36
View all 36 CVEs →
  • CVE-2024-9095CriMar 20, 2025
    risk 0.64cvss 9.8epss 0.01

    In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entire database. This includes sensitive data such as password hashes and secret API keys. The route is…

  • CVE-2024-7456CriNov 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without…

  • CVE-2025-5352CriAug 23, 2025
    risk 0.62cvss 9.6epss 0.01

    A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary versions up to 1.9.23, where the NEXT_PUBLIC_CUSTOM_SCRIPT environment variable is directly injected into the DOM using dangerouslySetInnerHTML without any…

  • CVE-2024-7475CriOct 29, 2024
    risk 0.59cvss 9.1epss 0.01

    An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and theft of user…

  • CVE-2024-1739CriApr 16, 2024
    risk 0.59cvss 9.1epss 0.01

    lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address…

  • CVE-2024-5386HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijack another user's account by obtaining the password reset token. The vulnerability is triggered when…

  • CVE-2025-9803HigNov 25, 2025
    risk 0.57cvss 8.8epss 0.00

    lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is crucial for ensuring the token is…

  • CVE-2024-4146CriJun 8, 2024
    risk 0.57cvss 9.8epss 0.01

    In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to. Specifically, the vulnerability is located in the `checkProjectAccess`…

  • CVE-2024-5128HigJun 6, 2024
    risk 0.57cvss 8.8epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, update, or delete any dataset_prompt or dataset_prompt_variation within any dataset or…

  • CVE-2024-5133HigJun 6, 2024
    risk 0.53cvss 8.1epss 0.01

    In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifically, when a user initiates the password reset process, the recovery token is included in the response of the `GET…

  • CVE-2024-4151HigMay 20, 2024
    risk 0.53cvss 8.1epss 0.00

    An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to insufficient access control checks in the handling of PATCH and GET requests for template versions. This vulnerability allows…

  • CVE-2024-1626HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint. The vulnerability allows authenticated users to modify the name of any project within the system without proper authorization…

  • CVE-2024-8789HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The application allows users to upload their own regular expressions, which are then executed on the server side. Certain regular expressions can have exponential runtime…

  • CVE-2024-8764HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to a Denial of Service (DoS) condition, as certain regular expressions can cause excessive resource consumption, blocking…

  • CVE-2024-10272HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization by sending a GET request to the /v1/datasets endpoint without a valid authorization token.

  • CVE-2024-5277HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.00

    In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue…

  • CVE-2024-4148HigJun 1, 2024
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular expressions, which can significantly impact the response time of the…

  • CVE-2024-1738HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to retrieve the results of any organization's evaluation by simply…

  • CVE-2024-1902HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.00

    lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the lack of validation to check if a user is still part of an organization before allowing them to make…

  • CVE-2024-8765HigMar 20, 2025
    risk 0.48cvss 7.3epss 0.01

    In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including…