CVE-2026-22664
CVE-2026-22664
7.1
HighPublished:
Last updated:
Source:disclosure@vulncheck.com
Modified
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- Low
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- None
- Availability (Vulnerable)
- None
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account.
References
disclosure@vulncheck.com
https://gist.github.com/mdisec/27c0cac0ec6a8f3c8f85a18987ddb942disclosure@vulncheck.com
https://github.com/f/prompts.chat/commit/30a8f0470e0ba45e6be9c9f55220f4a9a6b91c99disclosure@vulncheck.com
https://www.vulncheck.com/advisories/prompts-chat-ssrf-via-fal-ai-media-status-polling134c704f-9b21-4f2e-91b3-4a467353bcc0
https://gist.github.com/mdisec/27c0cac0ec6a8f3c8f85a18987ddb942