CWE
862
EPSS
0.043%
Advisory Published
Updated

CVE-2024-5127: Improper Access Control in lunary-ai/lunary

First published: Thu Jun 06 2024(Updated: )

In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any role, including those intended for Paid and Enterprise plans only. This issue arises due to insufficient backend validation of roles and permissions, enabling unauthorized users to join a project and potentially exploit roles and permissions not intended for their use. The vulnerability specifically affects the Team feature, where the backend fails to validate whether a user has paid for a plan before allowing them to send invite links with any role assigned. This could lead to unauthorized access and manipulation of project settings or data.

Credit: security@huntr.dev

Affected SoftwareAffected VersionHow to fix
lunary lunary>=1.2.2<1.2.25

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-5127?

    CVE-2024-5127 is considered a high severity vulnerability due to improper access controls affecting user roles.

  • How can I fix CVE-2024-5127?

    To fix CVE-2024-5127, upgrade to a version of lunary that is above 1.2.25, where this vulnerability has been addressed.

  • Who is affected by CVE-2024-5127?

    CVE-2024-5127 affects users on the Free plan of lunary versions 1.2.2 through 1.2.25.

  • What type of vulnerability is CVE-2024-5127?

    CVE-2024-5127 is classified as an improper access control vulnerability.

  • What impact does CVE-2024-5127 have on users?

    CVE-2024-5127 allows Free plan users to invite others and assign them roles reserved for Paid and Enterprise plan members.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203