{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T23:56:03.374","vulnerabilities":[{"cve":{"id":"CVE-2025-4962","sourceIdentifier":"security@huntr.dev","published":"2025-08-18T14:15:30.050","lastModified":"2026-06-17T09:34:23.937","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability allows authenticated users to create templates in another user's project by altering the `projectId` query parameter. The root cause of this issue is the absence of server-side validation to ensure that the authenticated user owns the specified `projectId`. The vulnerability has been addressed in version 1.9.23."},{"lang":"es","value":"Se identificó una vulnerabilidad de Referencia Directa a Objetos Insegura (IDOR) en el endpoint `POST /v1/templates` de la API de Lunary, que afecta a versiones hasta la 0.8.8. Esta vulnerabilidad permite a usuarios autenticados crear plantillas en el proyecto de otro usuario modificando el parámetro de consulta `projectId`. La causa principal de este problema es la ausencia de validación del lado del servidor para garantizar que el usuario autenticado posea el `projectId` especificado. Esta vulnerabilidad se ha solucionado en la versión 1.9.23."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"lunary-ai","product":"lunary-ai/lunary","versions":[{"version":"unspecified","lessThan":"1.9.23","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-18T14:00:34.991769Z","id":"CVE-2025-4962","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://github.com/lunary-ai/lunary/commit/e977d06f18a615963ffbe07e5bdff70218c29907","source":"security@huntr.dev"},{"url":"https://huntr.com/bounties/137a0aef-e243-49d4-832f-8e56056cba1a","source":"security@huntr.dev"}]}}]}