Home

Description

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20.

PUBLISHED Reserved 2026-05-29 | Published 2026-06-01 | Updated 2026-06-01 | Assigner cisa-cg




LOW: 2.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
MEDIUM: 5.0CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Default status
unknown

Any version before 2026-05-20
affected

2026-05-20
unaffected

Credits

Deflask13, CookieHanHoan

References

deepai.org/ (url) product

raw.githubusercontent.com/...IT/white/2026/va-26-152-01.json (url)

www.cve.org/CVERecord?id=CVE-2026-49433 (url)

cve.org (CVE-2026-49433)

nvd.nist.gov (CVE-2026-49433)

Download JSON