216.73.216.197

CVE-2026-22664

· Published 03/04/2026 21:17 · Modified 03/04/2026 21:17

Labels: CVE-2026-22664 2026-04-03CVE-2026-22664CWE-918[email protected]

Essential information

Published
03/04/2026 21:17
Modified
03/04/2026 21:17
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fal.ai / prompts.chat cpe:2.3:a:fal.ai:prompts.chat:*:*:*:*:*:*:*:*

References