Access Control Flaw in Lunary AI Before Version 1.5.9
CVE-2024-10762

8.1HIGH

Key Information:

Vendor

Lunary-ai

Vendor
CVE Published:
20 March 2025

What is CVE-2024-10762?

The Lunary AI platform, prior to version 1.5.9, contains a significant access control vulnerability in the /v1/evaluators/ endpoint. This issue permits users with insufficient privileges to execute DELETE requests, thereby enabling them to remove evaluators from a project without appropriate authorization. The absence of adequate middleware to verify user roles allows this exploitation, leading to potential permanent data loss and disruptions in project operations. It is essential for users and administrators to ensure they upgrade to the latest version to mitigate this risk.

Affected Version(s)

lunary-ai/lunary < 1.5.9

References

CVSS V3.0

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.