Someone reported this same vulnerability to us via HackerOne months ago. We worked with Sendgrid support to re-claim the domain and they said they were urgently working to fix the issue, or not.
Edit: just saw this post was from September. Author probably made thousands in rewards circulating this vulnerability.
I think, as with any tool, there's a time and place where it can be useful. Personally, I don't like to use Cucumber, but I've seen a couple of Rails apps that used it sparingly for integration tests and it worked wonders.
Edit: just saw this post was from September. Author probably made thousands in rewards circulating this vulnerability.