CVE-2026-103591 Details
Description
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
A vulnerability allowing unauthenticated arbitrary file read has been identified in DeepWiki-Open, specifically in versions through commit d92819a. The issue arises in the GET /codemap/file endpoint, where the repo_url parameter can be manipulated to bypass path containment checks. Attackers can specify absolute file paths to access any file available to the API process.
The application should be updated to restrict file access to a designated safe directory, preventing traversal outside of this area. Additionally, the path checks should be revised to accurately confine access to within the application's controlled environment.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AsyncFuncAI DeepWiki-Open | <= d92819a |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion