CVE-2026-103591 PUBLISHED

DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file

Assigner: VulnCheck
Reserved: 30.09.2026 Published: 30.09.2026 Updated: 30.09.2026

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor AsyncFuncAI
Product deepwiki-open
Versions Default: unaffected
  • affected from 0 to d92819a (incl.)

Credits

  • Trần Minh Huy finder

References

Problem Types

  • External Control of File Name or Path CWE