Stored Cross-Site Scripting Vulnerability in Lunary by Lunary-AI
CVE-2025-0281
What is CVE-2025-0281?
A stored cross-site scripting vulnerability exists in Lunary versions 1.6.7 and earlier, where an attacker can inject harmful JavaScript into the SAML IdP XML metadata. This metadata is utilized to formulate the SAML login redirect URL, which is then improperly assigned to window.location.href without appropriate validation or sanitization. Consequently, this vulnerability permits the execution of arbitrary JavaScript within the user’s browser context, potentially leading to severe security breaches, including session hijacking and data theft. Users are advised to upgrade to version 1.7.10 to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lunary-ai/lunary < 1.7.10
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
