Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-4146

28
FAUCET Score

CVE-2024-4146 is a critical incorrect authorization vulnerability in lunary-ai/lunary v1.2.13, allowing unauthorized users to fully access and manipulate projects within an organization. The flaw stems from insufficient permission checks in the 'checkProjectAccess' method, which only verifies organizational membership rather than explicit project access rights. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity, leading to complete compromise of project resources, including data confidentiality, integrity, and availability. While not currently in CISA's KEV catalog, there is community discussion and media coverage, indicating awareness, though no public exploit code or Metasploit/Nuclei modules are yet available.

Impacted Technologies

VendorProductVersion(s)CPE
1.2.13CPE matchmatch criteria
cpe:2.3:a:lunary:lunary:1.2.13:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 22nd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: lunaryFixed in: 1.2.26

Vendor Advisories (1)

npmGHSA-w5xm-mx47-v7c8critical

lunary-ai/lunary allows users unauthorized access to projects

Jun 8, 2024

References

github.com / lunary-ai/lunary/commit/c43b6c62035f32ca455f66d5fd22ba661648cde7
Patch
huntr.com / bounties/a749e696-b398-4260-b2d0-b0054b9fffa7
ExploitIssue Tracking