Vulnerability Database

315,363

Total vulnerabilities in the database

CVE-2024-8765

In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.

  • Published: Mar 20, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-8765
  • Exploit:

No technical information available.

CWEs: