PT-2025-47979 · Lunary Ai · Lunary

CVE-2025-9803

·

Published

2025-11-25

·

Updated

2026-07-01

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version 1.9.34
Description Improper authentication in the Google OAuth integration allows for account takeover. The application fails to verify the aud (audience) field in the access token issued by Google, which is necessary to ensure the token was intended for the specific application. This flaw enables attackers to use tokens issued to malicious applications to gain unauthorized access to user accounts.
Recommendations Update lunary-ai/lunary to version 1.9.35.

Exploit

Fix

Incorrect Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9803

Affected Products

Lunary