Description
In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include billing permissions. This can lead to a privilege escalation scenario where an administrator can manage billing, effectively bypassing the intended role-based access control. Only users with the 'owner' role should be allowed to invite members with billing permissions. This flaw allows admins to circumvent those restrictions, gaining unauthorized access and control over billing information, posing a risk to the organization’s financial resources.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/863ee34b-c4c6-4325-bf7a-82a7feebf88f
Scores
CVSS v3
7.3
EPSS
0.0047
EPSS Percentile
36.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-863
Status
published
Products (1)
lunary/lunary
< 1.5.7
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026