Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 13 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fka
Fka prompts.chat |
|
| CPEs | cpe:2.3:a:fka:prompts.chat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fka
Fka prompts.chat |
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F
F prompts.chat |
|
| Vendors & Products |
F
F prompts.chat |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic username resolution to impersonate victim accounts, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform. | |
| Title | prompts.chat Identity Confusion via Case-Sensitive Username Handling | |
| Weaknesses | CWE-178 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-06T18:02:55.883Z
Reserved: 2026-01-08T19:04:26.364Z
Link: CVE-2026-22665
Updated: 2026-04-06T18:00:51.565Z
Status : Analyzed
Published: 2026-04-03T21:17:09.693
Modified: 2026-04-13T18:10:46.217
Link: CVE-2026-22665
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:41:42Z