Vulnerabilities > Lunary > Lunary > 1.4.26
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-03-20 | CVE-2024-11300 | Unspecified vulnerability in Lunary In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. | 6.5 |
2025-03-20 | CVE-2024-9000 | Improper Authorization vulnerability in Lunary 1.4.26 In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. | 6.5 |
2025-03-20 | CVE-2024-9098 | Improper Access Control vulnerability in Lunary In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. | 6.1 |
2025-03-20 | CVE-2025-0281 | Cross-site Scripting vulnerability in Lunary A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. | 5.4 |