prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archives with unsanitized filenames containing path traversal sequences. Attackers can exploit missing server-side filename validation to inject path traversal sequences ../ into skill file archives, which when extracted by vulnerable tools write files outside the intended directory and overwrite shell initialization files to achieve code execution.
Cite this page
CVE-2026-22661. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-22661
Use CWE-22, Fka vendor hub and Prompts.Chat product page to widen CVE-2026-22661 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-22663, CVE-2026-22665 and CVE-2026-22664 for nearby disclosures in the same product family.