Executive brief
DeepAI, an artificial intelligence platform for image and text generation, was found to have a security flaw in its user account management system. An attacker could trick a logged-in user into clicking a malicious link, which would then automatically change the user's registered email address without their consent. This could lead to a complete takeover of the user's account, potentially exposing private AI generations and subscription data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the DeepAI 'change_user_email' API endpoint. The endpoint accepts POST requests to modify account email addresses without validating anti-CSRF tokens or similar protection mechanisms. An unauthenticated remote attacker can exploit this by hosting a malicious webpage that sends a forged request to the vulnerable endpoint when visited by an authenticated DeepAI user. Successful exploitation allows the attacker to update the account's email to one they control, subsequently facilitating a full account takeover through password reset procedures. The issue was remediated on May 20, 2026.
Affected products
- DeepAI DeepAI API All versions prior to 2026-05-20
Timeline
- 2026-05-20: patched: The vulnerability was fixed by the vendor.
- 2026-06-01: advisory: CVE-2026-49433 was published.