CVE-2026-49433 PUBLISHED

DeepAI api.deepai.org/change_user_email CSRF

Assigner: cisa-cg
Reserved: 29.05.2026 Published: 01.06.2026 Updated: 01.06.2026

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor DeepAI
Product api.deepai.org
Versions Default: unknown
  • affected from 0 to 2026-05-20 (excl.)
  • Version 2026-05-20 is unaffected

Credits

  • Deflask13, CookieHanHoan

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE