๐Ÿ” CVE Alert

CVE-2026-22663

HIGH 7.5

prompts.chat Authorization Bypass Information Disclosure

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
9th

prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized users to access sensitive data associated with private prompts. Attackers can exploit these missing authorization checks to retrieve private prompt version history, change requests, examples, current content, and metadata including titles and descriptions exposed via HTML meta tags.

CWE CWE-862
Vendor f
Product prompts.chat
Published Apr 3, 2026
Last Updated Apr 6, 2026
Stay Ahead of the Next One

Get instant alerts for f prompts.chat

Be the first to know when new high vulnerabilities affecting f prompts.chat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

f / prompts.chat
0 < 7b81836b214f2796aaf37ded2944eadc978afd35

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/f/prompts.chat/pull/1104 github.com: https://github.com/f/prompts.chat/commit/7b81836b214f2796aaf37ded2944eadc978afd35 vulncheck.com: https://www.vulncheck.com/advisories/prompts-chat-authorization-bypass-information-disclosure

Credits

Mehmet Ince @mdisec