CVE-2025-51867
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/07/2025
Last modified:
15/04/2026
Description
Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive information gained by the /browse/stories endpoint.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



