PT-2026-5650 · Lunary Ai · Lunary
CVE-2024-4147
·
Publicado
2026-02-02
·
Atualizado
2026-02-11
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version 1.2.13
Description
An insufficient granularity of access control allows users to delete prompts created in other organizations through ID manipulation. The application does not validate the ownership of the prompt before deletion, only checking for deletion permissions without verifying organizational affiliation. This can lead to legitimate users being unable to access removed prompts and cause information inconsistencies.
Recommendations
Ensure proper validation of prompt ownership before allowing deletion operations.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lunary