prompts.chat Authorization Bypass Vulnerability Allowing Unauthorized Access to Private Data

Vulnerability

A vulnerability exists in prompts.chat prior to commit 7b81836, where multiple authorization bypass issues allow unauthorized users to access sensitive information linked to private prompts. This flaw arises from the absence of proper privacy checks in various API endpoints and page metadata generation. Exploitation of this vulnerability enables access to private prompt version histories, change requests, examples, current content, and metadata such as titles and descriptions available through HTML meta tags.

Impact

Exploitation of this vulnerability could lead to unauthorized access to private prompt data, including version histories, change requests, examples, current content, and associated metadata.

Reproduction

To reproduce this vulnerability, access the API endpoints or pages that generate metadata for prompts. Since the isPrivate checks are missing, private prompts can be accessed without authorization, allowing retrieval of sensitive data such as prompt history and metadata.

Remediation

Users are advised to update to the latest version of prompts.chat, where this vulnerability has been addressed.

Added: Apr 3, 2026, 9:28 PM
Updated: Apr 3, 2026, 9:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
5.2
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.