Description
An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any prompts in any projects by supplying a specific prompt ID to an endpoint that does not adequately verify the ownership of the prompt ID. This issue was fixed in version 1.2.25.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/52c129f2-114e-492f-aee8-32c78f75ac4f
Scores
CVSS v3
6.5
EPSS
0.0022
EPSS Percentile
43.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
lunary/lunary
< 1.2.25
Published
Jun 06, 2024
Tracked Since
Feb 18, 2026