CVE-2026-22661 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: April 3, 2026
prompts.chat - Path Traversal & Remote Code Execution
Published: April 3, 2026Updated: April 3, 2026Remote Exploitable
Overview
prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability caused by unsanitized filenames in skill file ZIP archives, letting attackers write arbitrary files and achieve code execution, exploit requires crafted malicious ZIP files.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Attackers can write arbitrary files and execute code by exploiting path traversal in skill file extraction.
Mitigation
Update to the version including commit 0f8d4c3 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-22661
- Severity
- High
- CVSS Score
- 8.1
- Type
- path_traversal
- Status
- new
CWE
- CWE-22
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N