Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Deflask13

#49194of 53,619
5Total CVSS
Vulnerabilities · 1
PT-2026-45563
5.0
2026-06-01
Deepai · Api.Deepai.Org · CVE-2026-49433
The DeepAI endpoint 'https://api.deepai.org/change user email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20.