VYPR

Vendor CVEs

Lunary AI

All CVEs

71 total · sorted by risk
  • CVE-2024-7473MedOct 29, 2024
    risk 0.42cvss 6.5epss 0.00

    An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request. The issue is fixed in…

  • CVE-2024-7472MedOct 29, 2024
    risk 0.42cvss 6.5epss 0.00

    lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a…

  • CVE-2024-5248MedJun 6, 2024
    risk 0.42cvss 6.5epss 0.00

    In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` endpoint. The platform's role definitions restrict the `Prompt Editor` role to prompt management and project viewing/listing…

  • CVE-2024-5131MedJun 6, 2024
    risk 0.42cvss 6.5epss 0.00

    An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any prompts in any projects by supplying a specific prompt ID to an endpoint that does not…

  • CVE-2024-5126MedJun 6, 2024
    risk 0.42cvss 6.5epss 0.00

    An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but not including 1.2.25. The vulnerability allows unauthorized users to update…

  • CVE-2024-4154MedMay 21, 2024
    risk 0.42cvss 6.5epss 0.00

    In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to. Specifically, an unprivileged user can send a PATCH request to the project's endpoint with a new name for a project, despite not…

  • CVE-2024-3761HigMay 20, 2024
    risk 0.42cvss 7.5epss 0.00

    In lunary-ai/lunary version 1.2.2, the DELETE endpoint located at `packages/backend/src/api/v1/datasets` is vulnerable to unauthorized dataset deletion due to missing authorization and authentication mechanisms. This vulnerability allows any user, even those without a valid…

  • CVE-2024-1625MedApr 10, 2024
    risk 0.42cvss 6.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of any organization's project. The vulnerability is due to insufficient authorization checks in the project deletion endpoint, where…

  • CVE-2025-4779MedJul 7, 2025
    risk 0.40cvss 6.1epss 0.00

    lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaScript into the `v1/runs/ingest` endpoint by adding an empty `citations` field, triggering a code path where…

  • CVE-2024-9098MedMar 20, 2025
    risk 0.40cvss 6.1epss 0.01

    In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. This issue arises because the user creation endpoint does not restrict…

  • CVE-2024-5478MedJun 6, 2024
    risk 0.40cvss 6.1epss 0.00

    A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of lunary-ai/lunary version 1.2.7. The vulnerability arises due to the application's failure to escape or validate the `orgId` parameter supplied by the user before…

  • CVE-2025-0281MedMar 20, 2025
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript into the SAML IdP XML metadata, which is used to generate the SAML login redirect URL. This URL is then set as the value of…

  • CVE-2024-6867MedSep 13, 2024
    risk 0.35cvss 6.5epss 0.00

    An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it returns not only the…

  • CVE-2024-6087MedSep 13, 2024
    risk 0.35cvss 6.5epss 0.00

    An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invite user' functionality to obtain valid JWT tokens. These tokens can be used to…

  • CVE-2024-5127MedJun 6, 2024
    risk 0.35cvss 5.4epss 0.00

    In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any role, including those intended for Paid and Enterprise plans only. This issue arises due to insufficient backend…

  • CVE-2024-3504MedJun 6, 2024
    risk 0.35cvss 6.5epss 0.00

    An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is…

  • CVE-2024-5755MedJun 27, 2024
    risk 0.34cvss 5.3epss 0.00

    In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts with essentially the same email address (e.g., '[email protected]' and…

  • CVE-2024-1666MedApr 16, 2024
    risk 0.34cvss 5.3epss 0.00

    In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerability stems from the lack of server-side checks to verify if a user is on a free account during the radar creation process, which is only enforced in the web UI.…

  • CVE-2024-7476MedMar 20, 2025
    risk 0.28cvss 4.3epss 0.01

    A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending a crafted HTTP POST request to the /v1/templates/{id}/versions endpoint. This issue is…

  • CVE-2024-6086MedJun 27, 2024
    risk 0.28cvss 4.3epss 0.00

    In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor'…

  • CVE-2024-6582MedSep 13, 2024
    risk 0.21cvss 4.3epss 0.00

    A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to…

Page 2 of 2