CVE-2024-5126

A

n improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but not including 1.2.25. The vulnerability allows unauthorized users to update prompt details due to insufficient access control checks. This issue was addressed and fixed in version 1.2.25.

Configurations

Configuration 1 (hide)

cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*

History

15 Oct 2025, 13:15

Type Values Removed Values Added
CWE CWE-284 CWE-862

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://github.com/lunary-ai/lunary/commit/b7bd3a830a0f47ba07d0fd57bf78c4dd8a216297 - Patch () https://github.com/lunary-ai/lunary/commit/b7bd3a830a0f47ba07d0fd57bf78c4dd8a216297 - Patch
References () https://huntr.com/bounties/8e7e1267-ea6c-4789-b9dc-3410dfac6ec6 - Exploit, Issue Tracking, Patch, Third Party Advisory () https://huntr.com/bounties/8e7e1267-ea6c-4789-b9dc-3410dfac6ec6 - Exploit, Issue Tracking, Patch, Third Party Advisory

03 Oct 2024, 16:52

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 6.5
References () https://github.com/lunary-ai/lunary/commit/b7bd3a830a0f47ba07d0fd57bf78c4dd8a216297 - () https://github.com/lunary-ai/lunary/commit/b7bd3a830a0f47ba07d0fd57bf78c4dd8a216297 - Patch
References () https://huntr.com/bounties/8e7e1267-ea6c-4789-b9dc-3410dfac6ec6 - () https://huntr.com/bounties/8e7e1267-ea6c-4789-b9dc-3410dfac6ec6 - Exploit, Issue Tracking, Patch, Third Party Advisory
First Time Lunary
Lunary lunary
CPE cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*

07 Jun 2024, 14:56

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 19:16

Updated : 2025-10-15 13:15


NVD link : CVE-2024-5126

Mitre link : CVE-2024-5126

CVE.ORG link : CVE-2024-5126


JSON object : View

Products Affected
CWE
CWE-862

Missing Authorization

NVD-CWE-noinfo