Access Control Flaw in Lunary AI Allows Unauthorized Checklist Management
CVE-2024-9000
What is CVE-2024-9000?
The Lunary AI platform prior to version 1.4.26 exhibits a significant access control vulnerability in the checklists.post() endpoint. This weakness permits unauthorized users to create or modify checklists without proper validation of their permissions. Furthermore, it fails to enforce the uniqueness of the 'slug' field, enabling attackers to overwrite legitimate checklists by reusing existing slugs. This oversight could lead to data integrity problems, as vital checklists could be altered or replaced with malicious versions. It's crucial for users of Lunary AI to update to the latest version to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lunary-ai/lunary < 1.4.26
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
