Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lunary

First CVE: Apr 10, 2024Active for: 2 yearsTotal CVEs: 69
35.9
VTI Score
Medium

Lunary provides a focused artificial-intelligence and language-model platform, and despite its narrow product scope, occupies a prominent position in the vulnerability landscape for emerging AI infrastructure. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, concentrating around authorization and access-control weaknesses—including missing authorization checks, authorization bypasses through user-controlled keys, and improper authorization logic—that are characteristic of systems managing sensitive model access and data flows. The recurring pattern reflects the access-control complexity inherent to multi-tenant AI platforms where misconfigured permissions can expose models, training data, or inference results across user boundaries. Defenders should treat Lunary disclosures as high-priority, particularly in environments where the platform gates access to proprietary or sensitive language models. Current exploitation activity, severity breakdowns, and exposure counts are shown alongside this summary.

FAUCET AI Generated
69
Total CVEs
More Total CVEs than 99% of tracked vendors
23.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lunary over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2024
2 years ago
Most Recent CVE
Feb 2, 2026
172 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (69 CVEs).

69 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-5352CRITICAL
A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary versions up to 1.9.23, where the NEXT_PUBLIC_CUSTOM_SCRIPT environm
Aug 23, 20259.630NONO
CVE-2024-9095CRITICAL
In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entir
Mar 20, 20259.830NONO
CVE-2025-9803HIGH
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audi
Nov 25, 20258.828NONO
CVE-2024-7456CRITICAL
A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prio
Nov 1, 20249.828NONO
CVE-2024-4146CRITICAL
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they sh
Jun 8, 20249.828NONO
CVE-2024-5386HIGH
In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijac
Feb 2, 20268.827NONO
CVE-2024-7475CRITICAL
An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to
Oct 29, 20249.126NONO
CVE-2024-5328CRITICAL
A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability
Jun 6, 20249.325NONO
CVE-2024-1739CRITICAL
lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email add
Apr 16, 20249.125NONO
CVE-2024-1740CRITICAL
In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization
Apr 10, 20249.125NONO
View all 69 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products69 CVEs
41%
46%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network69 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low67 (97.1%)
High2 (2.9%)
Unknown0 (0.0%)
User Interaction
None58 (84.1%)
Unknown0 (0.0%)
Required11 (15.9%)
Privileges Required
Low33 (47.8%)
High2 (2.9%)
None34 (49.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (69 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lunary.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lunary — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lunary's Products

View all 1 CNAs →

Top CWEs