Impact
A path traversal flaw in the AsyncFuncAI deepwiki-open project, referenced by commit 16f35a0, permits unauthenticated attackers to supply an absolute filesystem path to the local-repository structure endpoint. This endpoint returns a directory listing without requiring authentication because its default WIKI_AUTH_MODE setting is false. Through the vulnerability, an adversary can enumerate sensitive files and directories on the host system, potentially exposing confidential data.
Affected Systems
The flaw affects the AsyncFuncAI deepwiki-open application. No specific version range is listed in the CNA data, but the vulnerability is present at least until the commit mentioned. Users running deepwiki-open without updating beyond the affected commit are susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and while the EPSS score is not available, the lack of a KEV listing suggests no public exploits are currently known. Nevertheless, as the flaw allows remote disclosure of arbitrary filesystem contents, attackers could advance further into the system if additional weaknesses exist. The attack vector is inferred to be remote over the network, exploiting the exposed endpoint that accepts absolute paths without validation.
OpenCVE Enrichment