CVE-2026-22662 Details
Description
prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches of user-controlled inputImageUrl parameters. Attackers can exploit this vulnerability by sending POST requests to the /api/media-generate endpoint to probe internal networks, access internal services, and exfiltrate data through the upstream Wiro service without receiving direct response bodies.
A blind server-side request forgery (SSRF) vulnerability has been identified in prompts.chat, prior to commit 1464475. This vulnerability resides in the Wiro media generator and allows authenticated users to send server-side requests using user-controlled inputImageUrl parameters. Exploitation involves sending POST requests to the /api/media-generate endpoint, which can be used to probe internal networks, access internal services, and exfiltrate data through the upstream Wiro service, all without receiving direct response bodies.
Users are advised to update to the latest version of prompts.chat, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/f/prompts.chat/commit/1464475df2698fb7ccd0cdbc382b0750466f891d | [email protected] | Patch |
| https://github.com/f/prompts.chat/pull/1102 | [email protected] | Issue TrackingMitigationVendor Advisory |
| https://www.vulncheck.com/advisories/prompts-chat-blind-ssrf-via-media-generate | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fka prompts.chat | < 2026-03-24 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | [email protected] |