CVE-2026-49433
DeepAI api.deepai.org/change_user_email CSRF
CVSS Score
5.0
EPSS Score
0.0%
EPSS Percentile
0th
The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20.
| CWE | CWE-352 |
| Vendor | deepai |
| Product | api.deepai.org |
| Published | Jun 1, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for deepai api.deepai.org
Be the first to know when new medium vulnerabilities affecting deepai api.deepai.org are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Affected Versions
DeepAI / api.deepai.org
0 < 2026-05-20
References
Credits
Deflask13, CookieHanHoan