Fka maintains a small portfolio of web-facing chat and messaging applications, including Prompts.chat and Textream, that expose user-facing network endpoints to familiar application-layer risks. The recurring vulnerability patterns center on server-side request forgery, path traversal, missing authorization checks, and case-sensitivity handling issues that are characteristic of web application validation and access-control boundaries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fka over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22665HIGH prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and re | Apr 3, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-22661HIGH prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting | Apr 3, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-22663HIGH prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that a | Apr 3, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-22664HIGH prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows authenticated users to perform arbi | Apr 3, 2026 | 7.7 | 28 | NO | NO |
CVE-2026-28403HIGH Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without | Mar 2, 2026 | 7.6 | 24 | NO | NO |
CVE-2026-28412HIGH Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer | Mar 2, 2026 | 7.5 | 22 | NO | NO |
CVE-2026-22662MEDIUM prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side f | Apr 3, 2026 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fka.
Media articles that mention a CVE ID that affects a product developed by Fka — matched by CVE ID, not by vendor name.