PT-2026-30226 · Fka+1 · Prompts.Chat
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
prompts.chat versions prior to commit 1464475
Description
Authenticated users can exploit a blind server-side request forgery (SSRF) in the Wiro media generator. This occurs when the application performs server-side fetches of the user-controlled
inputImageUrl parameter. By sending POST requests to the '/api/media-generate' endpoint, attackers can probe internal networks, access internal services, and exfiltrate data through the upstream Wiro service without receiving direct response bodies. Blind SSRF is a type of vulnerability where the attacker cannot see the response from the server they are targeting, but can still infer information based on the server's behavior.Recommendations
Update prompts.chat to commit 1464475 or later.
Avoid using the
inputImageUrl parameter in the '/api/media-generate' endpoint until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prompts.Chat