PT-2025-47979 · Lunary Ai · Lunary
CVE-2025-9803
·
Published
2025-11-25
·
Updated
2026-07-01
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version 1.9.34
Description
Improper authentication in the Google OAuth integration allows for account takeover. The application fails to verify the
aud (audience) field in the access token issued by Google, which is necessary to ensure the token was intended for the specific application. This flaw enables attackers to use tokens issued to malicious applications to gain unauthorized access to user accounts.Recommendations
Update lunary-ai/lunary to version 1.9.35.
Exploit
Fix
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunary