Impact
The vulnerability, identified as CWE-73, is an unauthenticated arbitrary file read in the GET /codemap/file endpoint of DeepWiki-Open. By providing a non‑URL repo_url value, an attacker can bypass path containment checks and retrieve any file that the API process can access, including sensitive configuration or secrets. This flaw allows full read access to the underlying filesystem without authentication.
Affected Systems
The affected product is AsyncFuncAI’s DeepWiki‑Open repository. No specific version range is listed in the CNA data, so all releases based on commit d92819a and before the fix are potentially impacted.
Risk and Exploitability
The CVSS score of 8.7 classifies the weakness as high severity. Because authentication is not required, the attack surface is broad. No EPSS score is available, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack path is a direct HTTP GET request to /codemap/file with a crafted repo_url parameter, which any web host or attacker with network reach to the API can execute.
OpenCVE Enrichment