CVE-2025-4962: fallo de gravedad alta en lunary-ai/lunary
IDOR Vulnerability in Template Creation via `projectId` Manipulation in lunary-ai/lunary
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.7epss 0.2%
probabilidad de explotación
0.2%top 86% de las CVE
explotación observada
noninguna fuente lo reporta
An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the `projectId` query parameter. The root cause of this issue is the absence of server-side validation to ensure that the authenticated user owns the specified `projectId`. The vulnerability has been addressed in version 1.9.23.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Productos afectados
lunary-ai · lunary-ai/lunaryCVEs relacionadas — lunary-ai/lunary
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-7476MEDIUMBroken Access Control in lunary-ai/lunaryEPSS 1.5%CVE-2024-7456CRITICALSQL Injection in lunary-ai/lunaryEPSS 1.4%CVE-2024-8765HIGHImproper Path Equivalence Resolution in lunary-ai/lunaryEPSS 0.8%CVE-2024-8789HIGHRegular Expression Denial of Service (ReDoS) in lunary-ai/lunaryEPSS 0.8%CVE-2024-8764HIGHImproper Authorization in lunary-ai/lunaryEPSS 0.8%CVE-2024-8763HIGHRegular Expression Denial of Service (ReDoS) in lunary-ai/lunaryEPSS 0.8%