PT-2026-30225 · Unknown · Prompts.Chat
Mdisec
·
Published
2026-04-03
·
Updated
2026-04-04
·
CVE-2026-22661
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
prompts.chat versions prior to commit 0f8d4c3
Description
prompts.chat before commit 0f8d4c3 has a path traversal flaw in how it handles skill files. Attackers can create malicious ZIP archives with filenames containing path traversal sequences, like
../, to write arbitrary files to the client system. The lack of server-side filename validation allows attackers to inject these sequences. Extracting these archives with vulnerable tools can lead to files being written outside the intended directory, potentially overwriting shell initialization files and achieving code execution.Recommendations
Update prompts.chat to commit 0f8d4c3 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prompts.Chat