CVE-2026-49433: Deepai Api.deepai.org

Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20.

Affected products

  • Deepai Api.deepai.org: before 2026-05-20 (fixed in 2026-05-20)

Published 2026-06-01. Last modified 2026-07-22.