PT-2026-30227 · Fka+1 · Prompts.Chat
CVE-2026-22663
·
Published
2026-04-03
·
Updated
2026-07-24
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
prompts.chat versions prior to commit 7b81836
Description
Multiple authorization bypass issues exist due to missing
isPrivate checks across API endpoints and during page metadata generation. This allows unauthorized users to access sensitive data associated with private prompts, including current content, version history, change requests, and examples. Additionally, metadata such as titles and descriptions are exposed via HTML meta tags.Recommendations
Update prompts.chat to commit 7b81836 or a later version.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prompts.Chat