CVE-2024-4146 is a critical incorrect authorization vulnerability in lunary-ai/lunary v1.2.13, allowing unauthorized users to fully access and manipulate projects within an organization. The flaw stems from insufficient permission checks in the 'checkProjectAccess' method, which only verifies organizational membership rather than explicit project access rights. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity, leading to complete compromise of project resources, including data confidentiality, integrity, and availability. While not currently in CISA's KEV catalog, there is community discussion and media coverage, indicating awareness, though no public exploit code or Metasploit/Nuclei modules are yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.13CPE matchmatch criteria | cpe:2.3:a:lunary:lunary:1.2.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.