HIGH
Improper Path Equivalence Resolution in lunary-ai/lunary
Published Mar 20, 2025
7.3
HIGHCVSS 3.0
EPSS 0.83%
Description
In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.4.23
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Lunary-AI | Lunary-Ai/lunary | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6895 Advisory
- https://github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fa Patch
- https://huntr.com/bounties/4908cfcf-607a-412a-9635-966cbb08bb49 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6895 | Advisory | |
| https://github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fa | Patch | |
| https://huntr.com/bounties/4908cfcf-607a-412a-9635-966cbb08bb49 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Reserved Sep 12, 2024
Link CVE-2024-8765
CISA Vulnrichment
Updated Mar 20, 2025
ENISA EUVD
EUVD-2025-6895 Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Exploited since n/a
Link EUVD-2025-6895