SQL Injection Vulnerability in Lunary API
CVE-2024-7456
What is CVE-2024-7456?
A SQL injection vulnerability has been identified in the /api/v1/external-users endpoint of Lunary AI's Lunary product, specifically in version v1.4.2. The vulnerability arises from the order by clause in an SQL query that utilizes an unsanitized input through sql.unsafe. This allows attackers to construct a malicious orderByClause without any server-side validation or sanitation, which can lead to execution of arbitrary SQL commands. Successful exploitation of this vulnerability has significant potential consequences, including complete data loss, unauthorized modification, or corruption of sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lunary-ai/lunary < 1.4.3
References
EPSS Score
23% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
