CVE-2024-45522: Linen
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.
Affected products
- Linen Linen: before 2024-04-03 (fixed in 2024-04-03)
Published 2024-09-02. Last modified 2026-06-17.