CVE-2024-5755: Lunary
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts with essentially the same email address (e.g., 'attacker123@gmail.com' and 'attacker.123@gmail.com'), leading to incorrect synchronization and potential security issues.
Affected products
- Lunary Lunary: up to and including 1.2.11
Published 2024-06-27. Last modified 2026-06-17.