CVE-2024-5133

HIGH

lunary-ai/lunary <1.2.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifically, when a user initiates the password reset process, the recovery token is included in the response of the `GET /v1/users/me/org` endpoint, which lists all users in a team. This allows any authenticated user to capture the recovery token of another user and subsequently change that user's password without consent, effectively taking over the account. The issue lies in the inclusion of the `recovery_token` attribute in the users object returned by the API.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0054
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (1)
lunary/lunary < 1.2.14
Published Jun 06, 2024
Tracked Since Feb 18, 2026