0.1.1
3 months ago
2 months ago
Known vulnerabilities in the prompts.chat package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
prompts.chat is a Developer toolkit for AI prompts - build, validate, parse, and connect to prompts.chat Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the Wiro How to fix Server-side Request Forgery (SSRF)? A fix was pushed into the | * |
prompts.chat is a Developer toolkit for AI prompts - build, validate, parse, and connect to prompts.chat Affected versions of this package are vulnerable to Directory Traversal through the handling of skill file archives containing unsanitized filenames with path traversal sequences. An attacker can write arbitrary files outside the intended directory and potentially overwrite critical files by submitting a crafted ZIP archive with malicious filenames. How to fix Directory Traversal? A fix was pushed into the | * |
prompts.chat is a Developer toolkit for AI prompts - build, validate, parse, and connect to prompts.chat Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths. An attacker can impersonate other users, replace profile content on canonical URLs, and inject attacker-controlled metadata and content across the platform by creating case-variant usernames that bypass uniqueness checks. How to fix Improper Handling of Case Sensitivity? A fix was pushed into the | * |
prompts.chat is a Developer toolkit for AI prompts - build, validate, parse, and connect to prompts.chat Affected versions of this package are vulnerable to Missing Authorization due to the missing How to fix Missing Authorization? A fix was pushed into the | * |
prompts.chat is a Developer toolkit for AI prompts - build, validate, parse, and connect to prompts.chat Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the How to fix Server-side Request Forgery (SSRF)? A fix was pushed into the | * |