CVE-2026-22665
HIGH EPSS 25.0%
Published Apr 3, 20262mo ago · Modified Jun 17, 20261w ago
8.6 CVSS 4.0
Published Apr 3, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago
Description
prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic username resolution to impersonate victim accounts, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
25.0% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-178
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| fka | prompts.chat | * | <2026-03-24 |
References 3
- github.com https://github.com/f/prompts.chat/commit/1464475df2698fb7ccd0cdbc382b0750466f891d
- github.com https://github.com/f/prompts.chat/pull/1098
- vulncheck.com https://www.vulncheck.com/advisories/prompts-chat-identity-confusion-via-case-sensitive-username-handling
Remediation
- github.com https://github.com/f/prompts.chat/commit/1464475df2698fb7ccd0cdbc382b0750466f891d