Description
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Arbitrary File Read
Action: Apply Patch
AI Analysis

Impact

The vulnerability, identified as CWE-73, is an unauthenticated arbitrary file read in the GET /codemap/file endpoint of DeepWiki-Open. By providing a non‑URL repo_url value, an attacker can bypass path containment checks and retrieve any file that the API process can access, including sensitive configuration or secrets. This flaw allows full read access to the underlying filesystem without authentication.

Affected Systems

The affected product is AsyncFuncAI’s DeepWiki‑Open repository. No specific version range is listed in the CNA data, so all releases based on commit d92819a and before the fix are potentially impacted.

Risk and Exploitability

The CVSS score of 8.7 classifies the weakness as high severity. Because authentication is not required, the attack surface is broad. No EPSS score is available, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack path is a direct HTTP GET request to /codemap/file with a crafted repo_url parameter, which any web host or attacker with network reach to the API can execute.

Generated by OpenCVE AI on October 1, 2026 at 00:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DeepWiki‑Open to a release that contains the patch removing the insecure handling of repo_url in the /codemap/file endpoint.
  • If an upgrade is not possible, disable the /codemap/file endpoint or restrict its access to trusted IP addresses.
  • Implement strict input validation for repo_url, allowing only properly formatted URLs and rejecting absolute filesystem paths.
  • Apply least privilege to the API process to limit the directories it can read.

Generated by OpenCVE AI on October 1, 2026 at 00:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
Title DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T23:02:35.721Z

Reserved: 2026-09-30T22:32:08.495Z

Link: CVE-2026-103591

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T23:16:58.773

Modified: 2026-09-30T23:16:58.907

Link: CVE-2026-103591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T01:00:10Z

Weaknesses
  • CWE-73

    External Control of File Name or Path