lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is crucial for ensuring the token is intended for the application. This oversight allows attackers to use tokens issued to malicious applications to gain unauthorized access to user accounts. The issue is resolved in version 1.9.35.
History

Tue, 25 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is crucial for ensuring the token is intended for the application. This oversight allows attackers to use tokens issued to malicious applications to gain unauthorized access to user accounts. The issue is resolved in version 1.9.35.
Title Improper Authentication in lunary-ai/lunary
Weaknesses CWE-287
References
Metrics cvssV3_0

{'score': 9.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-11-25T00:00:35.380Z

Updated: 2025-11-25T18:35:17.845Z

Reserved: 2025-09-01T13:06:49.733Z

Link: CVE-2025-9803

cve-icon Vulnrichment

Updated: 2025-11-25T18:35:07.280Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-25T01:15:47.137

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-9803

cve-icon Redhat

No data.