CVE-2024-8765
In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.81%
- CWE
- CWE-41
- Published
- 2025-03-20
- Last modified
- 2026-03-13
Affected products
- lunary-ai lunary-ai/lunary
Weakness type
Related vulnerabilities
- CVE-2026-85978 — Unauthenticated Remote Code Execution in Akana API Platform
- CVE-2025-24470 — An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.
- CVE-2022-0855 — Improper Resolution of Path Equivalence in microweber-dev/whmcs_plugin
- CVE-2026-57441 — MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
- CVE-2026-5816 — Improper Resolution of Path Equivalence in GitLab
- CVE-2023-46169 — IBM DS8900F file manipulation
- CVE-2026-72835 — filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
- CVE-2026-34451 — Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories