Loading HuntDB...

GHSA-8pg7-v7vv-p54p

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access to. Specifically, a user with a 'Member' role can issue a request to regenerate the private key of a project without having the necessary permissions or being assigned to that project. This issue was fixed in version 1.2.7.

Related CVEs

Key Information

GHSA ID
GHSA-8pg7-v7vv-p54p
Published
November 14, 2024 6:30 PM
Last Modified
November 14, 2024 6:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.