Cross-Site Request Forgery (CSRF) Vulnerability in Lunary Version 1.2.34
CVE-2024-6862
8.1HIGH
What is CVE-2024-6862?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Lunary AI's Lunary product, specifically in version 1.2.34. The flaw arises from overly permissive CORS settings that allow for all origins, thus exposing unauthenticated endpoints. Attackers can exploit this vulnerability to impersonate legitimate users, create projects, and perform tasks as if they had local access. This issue predominantly affects instances running locally on personal machines that are not publicly accessible. The existing CORS configuration does not adequately restrict access, which poses significant security risks.
Affected Version(s)
lunary-ai/lunary < 1.4.10