Account Hijacking Vulnerability in Lunary Product by Lunary AI
CVE-2024-5386
What is CVE-2024-5386?
In Lunary version 1.2.2, an account hijacking vulnerability is present, allowing users with a 'viewer' role to exploit a password reset token leak. This vulnerability arises when a lower-privileged user sends a specific request that triggers the server to return a password reset token in the 'recoveryToken' parameter. With this token, a malicious 'viewer' can reset the password of another user's account without any authorization. This excessive attack surface poses a significant risk, enabling privilege escalation and unauthorized account takeover.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lunary-ai/lunary < 1.2.14
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
