Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48392 | lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 15 Oct 2025 22:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-75 |
Wed, 15 Oct 2025 22:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-93 |
Tue, 15 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 01 Nov 2024 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lunary
Lunary lunary |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:lunary:lunary:1.2.26:*:*:*:*:*:*:* | |
| Vendors & Products |
Lunary
Lunary lunary |
|
| Metrics |
cvssV3_1
|
Wed, 30 Oct 2024 04:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lunary-ai
Lunary-ai lunary |
|
| CPEs | cpe:2.3:a:lunary-ai:lunary:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lunary-ai
Lunary-ai lunary |
|
| Metrics |
ssvc
|
Tue, 29 Oct 2024 22:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage. | |
| Title | Email Injection Vulnerability in lunary-ai/lunary | |
| Weaknesses | CWE-75 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-10-15T12:49:50.209Z
Reserved: 2024-08-04T13:38:41.689Z
Link: CVE-2024-7472
Updated: 2024-10-29T18:15:38.139Z
Status : Modified
Published: 2024-10-29T13:15:09.093
Modified: 2025-10-15T13:15:52.097
Link: CVE-2024-7472
No data.
OpenCVE Enrichment
No data.
EUVD