Medium severity6.5NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026
CVE-2024-7472
CVE-2024-7472
Description
lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data into outgoing emails by bypassing the extractFirstName function using a different whitespace character (e.g., \xa0). This vulnerability can be exploited to conduct phishing attacks, damage the application's brand, cause legal and compliance issues, and result in financial impact due to unauthorized email usage.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/lunary-ai/lunary/commit/a39837d7c49936a0c435d241f37ca2ea7904d2cdnvdPatch
- huntr.com/bounties/dc1feec6-1efb-4538-9b56-ab25deb80948nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.