In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.
References
Configurations
History
No history.
Information
Published : 2025-03-20 10:15
Updated : 2025-10-15 13:15
NVD link : CVE-2024-11300
Mitre link : CVE-2024-11300
CVE.ORG link : CVE-2024-11300
JSON object : View
Products Affected
lunary
- lunary
CWE
