CVE-2024-5386CWE-1125

Account Hijacking via Password Reset Token Leak in lunary-ai/lunary

Critical · published February 2, 2026

CVSS v3.0
9.6
EPSS
1%
Percentile
41.0
In the wild
Unconfirmed
What it is

🚨 A 'viewer' role user can snag a password reset token, turning them into an account hijacking ninja! 🔥 Imagine a library where a lowly book reader can somehow borrow the keys to the restricted sections just by asking the librarian nicely. That's what this vulnerability does—it lets someone with minimal privileges access the secrets of other users' accounts without a second thought! With this vulnerability, an attacker could gain full control over another user's account, compromising sensitive information and potentially wreaking havoc. It’s like handing a thief the keys to the kingdom—once they’re in, they can change passwords, access private data, or impersonate the victim. The fallout? Absolutely devastating!

Put simply

Imagine a library where a lowly book reader can somehow borrow the keys to the restricted sections just by asking the librarian nicely. That's what this vulnerability does—it lets someone with minimal privileges access the secrets of other users' accounts without a second thought! CVE-2024-5386 is an account hijacking vulnerability in lunary-ai/lunary version 1.2.2 where a user with a 'viewer' role can exploit a leaked password reset token to gain unauthorized access to another user's account, all due to a poorly controlled parameter in server responses.

What to do

With this vulnerability, an attacker could gain full control over another user's account, compromising sensitive information and potentially wreaking havoc. It’s like handing a thief the keys to the kingdom—once they’re in, they can change passwords, access private data, or impersonate the victim. The fallout? Absolutely devastating! To protect yourself, immediately patch to lunary version 1.2.3 or later. Additionally, review your role permissions to ensure no one outside of admin roles can access sensitive recovery tokens. Implement stricter validation checks on token requests. You've got this! Follow these steps, and you’ll be fortifying your defenses in no time! 🛡️

The record
Technical detail
CVSS v3.0
9.6 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00500 · 41.0th percentile
Weakness
CWE-1125 · Excessive Attack Surface
Published
2026-02-02T10:36Z
EPSS history
Timeline
  • 02 FEB 10:36Z
    Account Hijacking via Password Reset Token Leak in lunary-ai/lunary
    cvelistv5