Privilege Escalation in Lunary by Lunary AI
CVE-2024-10275
7.3HIGH
What is CVE-2024-10275?
In version 1.5.5 of Lunary by Lunary AI, a significant privilege escalation vulnerability allows administrators, without direct billing permissions, to alter user permissions to include access to billing features. This flaw enables unauthorized control over financial resources by bypassing the intended role-based access controls, creating a risk for organizations relying on secure financial management. Only users with the 'owner' role are authorized to grant billing permissions, but this vulnerability undermines that restriction, potentially jeopardizing sensitive billing information.
Affected Version(s)
lunary-ai/lunary < 1.5.7