API Key Exposure in Lunary AI Version 1.4.29
CVE-2024-9099
What is CVE-2024-9099?
In Lunary AI v1.4.29, the /projects API endpoint unintentionally exposes both public and private API keys, allowing users with minimal permissions, like Viewers or Prompt Editors, to access sensitive credentials. This significant exposure can lead to unauthorized actions being performed on behalf of projects, including the access of confidential data and potential deletion of project resources. The sensitive keys are discoverable through developer tools when the endpoint is accessed from the frontend, posing a substantial risk to project integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lunary-ai/lunary < 1.5.7
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
