CVE-2026-22664 identifies a Server-Side Request Forgery (SSRF) vulnerability in prompts.chat prior to commit 30a8f04, specifically affecting its Fal.ai media status polling. This high-severity vulnerability (CVSS 7.7) allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs due to a lack of URL validation. Exploitation can lead to the disclosure of the FAL_API_KEY, enabling credential theft, internal network probing, and unauthorized use of the victim's Fal.ai account. Currently, there is no evidence of active exploitation, public exploit code, or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-03-25CPE matchmatch criteria | cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.