CVE-2024-7472 describes an email injection vulnerability in lunary-ai/lunary v1.2.26, specifically within the Send email verification and Sign up APIs. An unauthenticated attacker can bypass input sanitization by using alternative whitespace characters, allowing them to inject arbitrary data into outgoing emails. This vulnerability carries a CVSS score of 6.5 (Medium) due to its network-based attack vector and low complexity, potentially leading to phishing attacks, brand damage, and compliance issues. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.26CPE matchmatch criteria | cpe:2.3:a:lunary:lunary:1.2.26:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.