{"id":"CVE-2024-5755","details":"In lunary-ai/lunary versions \u003c=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts with essentially the same email address (e.g., 'attacker123@gmail.com' and 'attacker.123@gmail.com'), leading to incorrect synchronization and potential security issues.","modified":"2026-05-04T08:48:37.447463Z","published":"2024-06-27T19:15:16.400Z","withdrawn":"2026-05-04T08:48:37.447463Z","references":[{"type":"EVIDENCE","url":"https://huntr.com/bounties/cf337d37-e602-482b-aa7a-9e34e7f13e1f"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5755.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"1.2.11"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}