{"id":"GHSA-9jmp-j63g-8x6m","summary":"Withdrawn Advisory: Lunary information disclosure vulnerability","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because the [lunary npm package](https://www.npmjs.com/package/lunary) is connected to https://github.com/lunary-ai/lunary-js, not the https://github.com/lunary-ai/lunary repo that is discussed in this advisory.\n\n**The underlying vulnerability report is still valid**, but it doesn't affect a product in a [GitHub Advisory Database supported ecosystem](https://docs.github.com/en/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/about-the-github-advisory-database#github-reviewed-advisories).\n\nThis link is maintained to preserve external references.\n\n## Original Description\nAn information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it returns not only the specified run but also all runs that have the `run_id` listed as their parent run. This issue affects the main branch, commit a761d833. The vulnerability allows unauthorized users to obtain information about non-public runs and their related runs, given the `run_id` of a public or non-public run.","aliases":["CVE-2024-6867"],"modified":"2026-09-10T03:50:56.017275267Z","published":"2024-09-13T18:31:48Z","withdrawn":"2025-06-20T20:00:15Z","database_specific":{"cwe_ids":["CWE-1220"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-09-13T19:34:16Z","nvd_published_at":"2024-09-13T17:15:13Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6867"},{"type":"WEB","url":"https://github.com/lunary-ai/lunary/commit/35afd4439464571eb016318cd7b6f85a162225ca"},{"type":"WEB","url":"https://huntr.com/bounties/460df515-164c-4435-954b-0233a181545f"}],"affected":[{"package":{"name":"lunary","ecosystem":"npm","purl":"pkg:npm/lunary"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-9jmp-j63g-8x6m/GHSA-9jmp-j63g-8x6m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}