Stored Cross-Site Scripting Flaw in Lunary by Lunary AI
CVE-2025-4779
What is CVE-2025-4779?
Lunary AI's Lunary software, specifically versions prior to 1.9.24, is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows unauthenticated attackers to exploit the v1/runs/ingest endpoint by injecting malicious JavaScript through an empty citations field. The vulnerability arises when the application improperly utilizes dangerouslySetInnerHTML, which can lead to the execution of arbitrary JavaScript within users’ browsers. Consequently, this can result in various security risks, including session hijacking and the potential theft of sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lunary-ai/lunary < 1.9.24
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
