VYPR
Critical severity9.8NVD Advisory· Published Sep 2, 2024· Updated Jun 17, 2026

CVE-2024-45522

CVE-2024-45522

Description

Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Linen/Linen3 versions
    cpe:2.3:a:linen:linen:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:linen:linen:*:*:*:*:*:*:*:*range: <2024-04-03
    • (no CPE)
    • (no CPE)range: <cd37c3e

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.