Stored Cross-Site Scripting Flaw in Lunary by Lunary AI
CVE-2025-4779
9.1CRITICAL
What is CVE-2025-4779?
Lunary AI's Lunary software, specifically versions prior to 1.9.24, is susceptible to a stored cross-site scripting (XSS) vulnerability. This issue allows unauthenticated attackers to exploit the v1/runs/ingest
endpoint by injecting malicious JavaScript through an empty citations
field. The vulnerability arises when the application improperly utilizes dangerouslySetInnerHTML
, which can lead to the execution of arbitrary JavaScript within users’ browsers. Consequently, this can result in various security risks, including session hijacking and the potential theft of sensitive data.
Affected Version(s)
lunary-ai/lunary < 1.9.24