CVE-2026-22662: Fka Prompts.chat

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches of user-controlled inputImageUrl parameters. Attackers can exploit this vulnerability by sending POST requests to the /api/media-generate endpoint to probe internal networks, access internal services, and exfiltrate data through the upstream Wiro service without receiving direct response bodies.

Affected products

  • Fka Prompts.chat: before 2026-03-24 (fixed in 2026-03-24)

Published 2026-04-03. Last modified 2026-07-24.