Home

Description

lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is crucial for ensuring the token is intended for the application. This oversight allows attackers to use tokens issued to malicious applications to gain unauthorized access to user accounts. The issue is resolved in version 1.9.35.

PUBLISHED Reserved 2025-09-01 | Published 2025-11-25 | Updated 2025-11-25 | Assigner @huntr_ai




CRITICAL: 9.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Problem types

CWE-287 Improper Authentication

Product status

Any version before 1.9.35
affected

References

huntr.com/bounties/4734f35f-514c-4d10-98fa-3a54514f6af6 exploit

huntr.com/bounties/4734f35f-514c-4d10-98fa-3a54514f6af6

github.com/...ommit/95a2cc8e012bf5f089edbfa072ba66dcb7e10d91

cve.org (CVE-2025-9803)

nvd.nist.gov (CVE-2025-9803)

Download JSON