CVE-2024-1739 | Case Insensitive Email Address Validation Vulnerability in lunary-ai/lunary
Exp
lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address by varying the case of the email characters. For example, accounts for '[email protected]' and '[email protected]' can both be created, leading to potential impersonation and confusion among users.
Conclusion & alert: CVE-2024-1739 is rated High Exploit Risk (66.5/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.56%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2024-1739
Exploit prediction scoring system (EPSS) score for CVE-2024-1739
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).