Privilege Escalation in Lunary by Lunary AI
CVE-2024-10275

7.3HIGH

Key Information:

Vendor

Lunary-ai

Vendor
CVE Published:
20 March 2025

What is CVE-2024-10275?

In version 1.5.5 of Lunary by Lunary AI, a significant privilege escalation vulnerability allows administrators, without direct billing permissions, to alter user permissions to include access to billing features. This flaw enables unauthorized control over financial resources by bypassing the intended role-based access controls, creating a risk for organizations relying on secure financial management. Only users with the 'owner' role are authorized to grant billing permissions, but this vulnerability undermines that restriction, potentially jeopardizing sensitive billing information.

Affected Version(s)

lunary-ai/lunary < 1.5.7

References

CVSS V3.0

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.