Junglewise Threat Intelligence

Lunary-ai Lunary access control bypass in prompt variation management

Severity: low · CVSS 3.1 · Published 2024-06-10

Technologies: lunary (npm). Vendors: npm.

Executive brief

Lunary, an observability platform for AI applications, contains a security flaw in how it manages AI prompt variations. This vulnerability allows a user from one organization to view, modify, or delete prompt data belonging to a completely different organization. This could lead to the theft of proprietary AI prompts or the disruption of AI experiments and production workflows.

Technical details

An Insecure Direct Object Reference (IDOR) or insufficient granularity of access control exists in Lunary version 1.2.13 and prior. The application fails to validate that the dataset prompts and variations being accessed or modified belong to the requesting user's organization or project. An authenticated attacker can exploit this by sending crafted network requests to create, update, or delete prompt variations for datasets they do not own. This can result in unauthorized data access and loss of data integrity for AI training and testing datasets. The issue was addressed in version 1.4.9.

Affected products

  • lunary-ai lunary up to 1.4.8

Timeline

  • 2024-06-09: disclosed
  • 2024-06-10: advisory
  • 2024-06-10: patched: Fixed in version 1.4.9

References

Related threats