Lunary provides a focused artificial-intelligence and language-model platform, and despite its narrow product scope, occupies a prominent position in the vulnerability landscape for emerging AI infrastructure. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, concentrating around authorization and access-control weaknesses—including missing authorization checks, authorization bypasses through user-controlled keys, and improper authorization logic—that are characteristic of systems managing sensitive model access and data flows. The recurring pattern reflects the access-control complexity inherent to multi-tenant AI platforms where misconfigured permissions can expose models, training data, or inference results across user boundaries. Defenders should treat Lunary disclosures as high-priority, particularly in environments where the platform gates access to proprietary or sensitive language models. Current exploitation activity, severity breakdowns, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lunary over time
Signals from CVEs in this vendor scope (69 CVEs).
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5352CRITICAL A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary versions up to 1.9.23, where the NEXT_PUBLIC_CUSTOM_SCRIPT environm | Aug 23, 2025 | 9.6 | 30 | NO | NO |
CVE-2024-9095CRITICAL In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entir | Mar 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-9803HIGH lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audi | Nov 25, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-7456CRITICAL A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prio | Nov 1, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-4146CRITICAL In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they sh | Jun 8, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-5386HIGH In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijac | Feb 2, 2026 | 8.8 | 27 | NO | NO |
CVE-2024-7475CRITICAL An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to | Oct 29, 2024 | 9.1 | 26 | NO | NO |
CVE-2024-5328CRITICAL A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability | Jun 6, 2024 | 9.3 | 25 | NO | NO |
CVE-2024-1739CRITICAL lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email add | Apr 16, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-1740CRITICAL In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization | Apr 10, 2024 | 9.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (69 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lunary.
Media articles that mention a CVE ID that affects a product developed by Lunary — matched by CVE ID, not by vendor name.