LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-22661

CVE-2026-22661 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 3, 2026

prompts.chat - Path Traversal & Remote Code Execution

Published: April 3, 2026Updated: April 3, 2026Remote Exploitable

Overview

prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability caused by unsanitized filenames in skill file ZIP archives, letting attackers write arbitrary files and achieve code execution, exploit requires crafted malicious ZIP files.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Attackers can write arbitrary files and execute code by exploiting path traversal in skill file extraction.

Mitigation

Update to the version including commit 0f8d4c3 or later.

Details

CVE ID
CVE-2026-22661
Severity
High
CVSS Score
8.1
Type
path_traversal
Status
new

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N