PT-2026-5650 · Lunary Ai · Lunary

CVE-2024-4147

·

Publicado

2026-02-02

·

Atualizado

2026-02-11

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version 1.2.13
Description An insufficient granularity of access control allows users to delete prompts created in other organizations through ID manipulation. The application does not validate the ownership of the prompt before deletion, only checking for deletion permissions without verifying organizational affiliation. This can lead to legitimate users being unable to access removed prompts and cause information inconsistencies.
Recommendations Ensure proper validation of prompt ownership before allowing deletion operations.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-4147

Produtos afetados

Lunary