CVE-2025-5352 is a critical stored Cross-Site Scripting (XSS) vulnerability affecting lunary-ai/lunary versions up to 1.9.23. This flaw allows arbitrary JavaScript execution due to unsanitized injection of the NEXT_PUBLIC_CUSTOM_SCRIPT environment variable into the DOM. With a CVSS score of 9.6 (CRITICAL), successful exploitation can lead to complete account takeover, data exfiltration, and persistent attacks across all users. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, but the vulnerability has garnered some community discussion. The issue is fixed in version 1.9.25.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.25CPE matchmatch criteria | cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.