Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 13 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fka
Fka prompts.chat |
|
| CPEs | cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fka
Fka prompts.chat |
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F
F prompts.chat |
|
| Vendors & Products |
F
F prompts.chat |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches of user-controlled inputImageUrl parameters. Attackers can exploit this vulnerability by sending POST requests to the /api/media-generate endpoint to probe internal networks, access internal services, and exfiltrate data through the upstream Wiro service without receiving direct response bodies. | |
| Title | prompts.chat Blind SSRF via media-generate | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-06T15:29:29.152Z
Reserved: 2026-01-08T19:04:26.364Z
Link: CVE-2026-22662
Updated: 2026-04-06T15:03:47.957Z
Status : Analyzed
Published: 2026-04-03T21:17:09.163
Modified: 2026-04-13T18:18:49.627
Link: CVE-2026-22662
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:41:45Z