CVE-2026-22661 describes a high-severity path traversal vulnerability affecting prompts.chat prior to commit 0f8d4c3. This flaw allows attackers to craft malicious ZIP archives with unsanitized filenames containing path traversal sequences, enabling arbitrary file writes to the client system. Rated 8.1 High on the CVSS scale, successful exploitation could lead to code execution by overwriting shell initialization files, requiring user interaction but with low attack complexity. While not currently listed on CISA's KEV catalog and lacking public exploit code, it is on a "Hot List" and has garnered minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-03-25CPE matchmatch criteria | cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.