CVE-2024-45522: Linen

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.

Affected products

  • Linen Linen: before 2024-04-03 (fixed in 2024-04-03)

Published 2024-09-02. Last modified 2026-06-17.