CVE-2026-22665

prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic username resolution to impersonate victim accounts, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) prompts.chat anterior al commit 1464475 contiene una vulnerabilidad de confusión de identidad debido a un manejo inconsistente de nombres de usuario, tanto sensible a mayúsculas y minúsculas como insensible a mayúsculas y minúsculas, en las rutas de escritura y lectura, permitiendo a los atacantes crear nombres de usuario con variantes de mayúsculas y minúsculas que eluden las comprobaciones de unicidad. Los atacantes pueden explotar la resolución no determinista de nombres de usuario para suplantar cuentas de víctimas, reemplazar el contenido del perfil en URL canónicas e inyectar metadatos y contenido controlados por el atacante en toda la plataforma.

26 May 2026, 14:16

Type Values Removed Values Added
Summary (en) prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic username resolution to impersonate victim accounts, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform. (en) prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic username resolution to impersonate victim accounts, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform.

13 Apr 2026, 18:10

Type Values Removed Values Added
References () https://github.com/f/prompts.chat/commit/1464475df2698fb7ccd0cdbc382b0750466f891d - () https://github.com/f/prompts.chat/commit/1464475df2698fb7ccd0cdbc382b0750466f891d - Patch
References () https://github.com/f/prompts.chat/pull/1098 - () https://github.com/f/prompts.chat/pull/1098 - Exploit, Issue Tracking, Vendor Advisory
References () https://www.vulncheck.com/advisories/prompts-chat-identity-confusion-via-case-sensitive-username-handling - () https://www.vulncheck.com/advisories/prompts-chat-identity-confusion-via-case-sensitive-username-handling - Third Party Advisory
CPE cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:*
First Time Fka
Fka prompts.chat

03 Apr 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 21:17

Updated : 2026-07-24 22:10


NVD link : CVE-2026-22665

Mitre link : CVE-2026-22665

CVE.ORG link : CVE-2026-22665


JSON object : View

Products Affected

fka

  • prompts.chat
CWE
CWE-178

Improper Handling of Case Sensitivity