Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 13 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fka
Fka prompts.chat |
|
| CPEs | cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fka
Fka prompts.chat |
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F
F prompts.chat |
|
| Vendors & Products |
F
F prompts.chat |
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account. | |
| Title | prompts.chat SSRF via Fal.ai Media Status Polling | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:19:51.012Z
Reserved: 2026-01-08T19:04:26.364Z
Link: CVE-2026-22664
Updated: 2026-04-07T14:19:39.533Z
Status : Analyzed
Published: 2026-04-03T21:17:09.513
Modified: 2026-04-13T18:13:53.827
Link: CVE-2026-22664
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:41:43Z