CVE-2026-22664

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) prompts.chat anterior al commit 30a8f04 contiene una vulnerabilidad de falsificación de petición del lado del servidor en el sondeo de estado de medios de Fal.ai que permite a usuarios autenticados realizar peticiones salientes arbitrarias al proporcionar URLs controladas por el atacante en el parámetro token. Los atacantes pueden explotar la falta de validación de URL para divulgar la FAL_API_KEY en la cabecera de Autorización, lo que permite el robo de credenciales, el sondeo de red interno y el abuso de la cuenta de Fal.ai de la víctima.

26 May 2026, 14:16

Type Values Removed Values Added
Summary (en) prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account. (en) prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account.

13 Apr 2026, 18:13

Type Values Removed Values Added
References () https://gist.github.com/mdisec/27c0cac0ec6a8f3c8f85a18987ddb942 - () https://gist.github.com/mdisec/27c0cac0ec6a8f3c8f85a18987ddb942 - Exploit, Third Party Advisory
References () https://github.com/f/prompts.chat/commit/30a8f0470e0ba45e6be9c9f55220f4a9a6b91c99 - () https://github.com/f/prompts.chat/commit/30a8f0470e0ba45e6be9c9f55220f4a9a6b91c99 - Patch
References () https://www.vulncheck.com/advisories/prompts-chat-ssrf-via-fal-ai-media-status-polling - () https://www.vulncheck.com/advisories/prompts-chat-ssrf-via-fal-ai-media-status-polling - Third Party Advisory
CPE cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:*
First Time Fka
Fka prompts.chat

07 Apr 2026, 15:17

Type Values Removed Values Added
References () https://gist.github.com/mdisec/27c0cac0ec6a8f3c8f85a18987ddb942 - () https://gist.github.com/mdisec/27c0cac0ec6a8f3c8f85a18987ddb942 -

03 Apr 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 21:17

Updated : 2026-07-24 22:10


NVD link : CVE-2026-22664

Mitre link : CVE-2026-22664

CVE.ORG link : CVE-2026-22664


JSON object : View

Products Affected

fka

  • prompts.chat
CWE
CWE-918

Server-Side Request Forgery (SSRF)