Vulnerability Description
prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic username resolution to impersonate victim accounts, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fka | Prompts.Chat | < 2026-03-24 |
Related Weaknesses (CWE)
References
- https://github.com/f/prompts.chat/commit/1464475df2698fb7ccd0cdbc382b0750466f891Patch
- https://github.com/f/prompts.chat/pull/1098ExploitIssue TrackingVendor Advisory
- https://www.vulncheck.com/advisories/prompts-chat-identity-confusion-via-case-seThird Party Advisory
FAQ
What is CVE-2026-22665?
CVE-2026-22665 is a vulnerability with a CVSS score of 8.1 (HIGH). prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing at...
How severe is CVE-2026-22665?
CVE-2026-22665 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-22665?
Check the references section above for vendor advisories and patch information. Affected products include: Fka Prompts.Chat.