PT-2026-30225 · Unknown · Prompts.Chat

·

CVE-2026-22661

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions prompts.chat versions prior to commit 0f8d4c3
Description prompts.chat before commit 0f8d4c3 has a path traversal flaw in how it handles skill files. Attackers can create malicious ZIP archives with filenames containing path traversal sequences, like ../, to write arbitrary files to the client system. The lack of server-side filename validation allows attackers to inject these sequences. Extracting these archives with vulnerable tools can lead to files being written outside the intended directory, potentially overwriting shell initialization files and achieving code execution.
Recommendations Update prompts.chat to commit 0f8d4c3 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22661

Affected Products

Prompts.Chat