216.73.216.197

CVE-2026-49433

· Published 01/06/2026 21:16 · Modified 02/06/2026 13:04

Labels: CVE-2026-49433 2026-06-019119a7d8-5eab-497f-8521-727c672e3725CVE-2026-49433CWE-352

Essential information

Published
01/06/2026 21:16
Modified
02/06/2026 13:04
Author
Creator
CVSS
2.3 LOW (v3) 2.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
deepai / deepai api cpe:2.3:a:deepai:deepai_api:*:*:*:*:*:*:*:*

References