prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic username resolution to impersonate victim accounts, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform.
Use CWE-178, Fka vendor hub and Prompts.Chat product page to widen CVE-2026-22665 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-22663, CVE-2026-22661 and CVE-2026-22664 for nearby disclosures in the same product family.