Account Hijacking Vulnerability in Lunary Product by Lunary AI
CVE-2024-5386

9.6CRITICAL

Key Information:

Vendor

Lunary-ai

Vendor
CVE Published:
2 February 2026

What is CVE-2024-5386?

In Lunary version 1.2.2, an account hijacking vulnerability is present, allowing users with a 'viewer' role to exploit a password reset token leak. This vulnerability arises when a lower-privileged user sends a specific request that triggers the server to return a password reset token in the 'recoveryToken' parameter. With this token, a malicious 'viewer' can reset the password of another user's account without any authorization. This excessive attack surface poses a significant risk, enabling privilege escalation and unauthorized account takeover.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

lunary-ai/lunary < 1.2.14

References

CVSS V3.0

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.