CVE-2025-51867
MEDIUM 6.5EPSS 0.3%
Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive information gained by the /browse/stories endpoint.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS
- 0.31% chance of exploitation in the next 30 days, 24th percentile
- Published
- 2025-07-22
- Updated
- 2025-07-23
Proof-of-concept exploits (1)
- Secsys-FDU/CVE-2025-518670★ · 2025-07-19