Stored Cross-Site Scripting Flaw in Lunary by Lunary AI
CVE-2025-4779

9.1CRITICAL

Key Information:

Vendor

Lunary-ai

Vendor
CVE Published:
7 July 2025

What is CVE-2025-4779?

Lunary AI's Lunary software, specifically versions prior to 1.9.24, is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows unauthenticated attackers to exploit the v1/runs/ingest endpoint by injecting malicious JavaScript through an empty citations field. The vulnerability arises when the application improperly utilizes dangerouslySetInnerHTML, which can lead to the execution of arbitrary JavaScript within users’ browsers. Consequently, this can result in various security risks, including session hijacking and the potential theft of sensitive data.

Affected Version(s)

lunary-ai/lunary < 1.9.24

References

CVSS V3.0

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-4779 : Stored Cross-Site Scripting Flaw in Lunary by Lunary AI