CVE detail
CVE-2024-10273 — CVE-2024-10273
Published 2025-03-20 · Modified 2026-06-17 · Vendor lunary · Product lunary · Source nvd
MEDIUM
severity
CVSS-derived band
0.0040
EPSS probability
exploitation probability, 30d
33.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have appropriate privilege checks, enabling low-privilege users to update models they should not have access to modify. This vulnerability could lead to unauthorized changes in critical resources, affecting the integrity and reliability of the system.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References