CVE-2024-5126

An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but not including 1.2.25. The vulnerability allows unauthorized users to update prompt details due to insufficient access control checks. This issue was addressed and fixed in version 1.2.25.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*

History

15 Oct 2025, 13:15

Type Values Removed Values Added
CWE CWE-284 CWE-862

Information

Published : 2024-06-06 19:16

Updated : 2025-10-15 13:15


NVD link : CVE-2024-5126

Mitre link : CVE-2024-5126

CVE.ORG link : CVE-2024-5126


JSON object : View

Products Affected

lunary

  • lunary
CWE
CWE-862

Missing Authorization

NVD-CWE-noinfo