PT-2026-30225 · Unknown · Prompts.Chat

Mdisec

·

Published

2026-04-03

·

Updated

2026-04-04

·

CVE-2026-22661

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions prompts.chat versions prior to commit 0f8d4c3
Description prompts.chat before commit 0f8d4c3 has a path traversal flaw in how it handles skill files. Attackers can create malicious ZIP archives with filenames containing path traversal sequences, like ../, to write arbitrary files to the client system. The lack of server-side filename validation allows attackers to inject these sequences. Extracting these archives with vulnerable tools can lead to files being written outside the intended directory, potentially overwriting shell initialization files and achieving code execution.
Recommendations Update prompts.chat to commit 0f8d4c3 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-22661

Affected Products

Prompts.Chat