Loading HuntDB...

GHSA-7g45-4xm2-qxvf

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, update, or delete any dataset_prompt or dataset_prompt_variation within any dataset or project. The issue stems from improper access control checks in the dataset management endpoints, where direct references to object IDs are not adequately secured against unauthorized access. This vulnerability was fixed in version 1.2.25.

Related CVEs

Key Information

GHSA ID
GHSA-7g45-4xm2-qxvf
Published
June 6, 2024 9:30 PM
Last Modified
June 6, 2024 9:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.