Account Takeover Vulnerability in Lunary AI by Lunary
CVE-2025-9803
9.3CRITICAL
What is CVE-2025-9803?
Lunary AI version 1.9.34 is susceptible to account takeover attacks due to a flaw in its Google OAuth integration. The application improperly verifies the 'aud' (audience) field in access tokens issued by Google, which is essential for ensuring the token is valid for the intended application. This vulnerability allows attackers to exploit tokens that are intended for malicious applications, granting them unauthorized access to user accounts. This issue has been addressed in version 1.9.35.
Affected Version(s)
lunary-ai/lunary < 1.9.35
