CVE-2026-22663 is an authorization bypass vulnerability affecting prompts.chat prior to commit 7b81836, stemming from missing `isPrivate` checks across API endpoints and page metadata generation. This allows unauthorized users to access sensitive private prompt data, including version history, content, and metadata. With a CVSS score of 7.5 (High), it can be exploited remotely without authentication or user interaction, leading to a high confidentiality impact. Currently, there are no known public exploits, active exploitation, or Metasploit/Nuclei modules, though the vulnerability has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-03-25CPE matchmatch criteria | cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.