Description
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

DeepWiki-Open includes an arbitrary file read flaw in its unauthenticated /ws/chat WebSocket endpoint. The endpoint accepts a repo_url parameter that is interpreted as a filesystem path without any containment checks, allowing an attacker to supply arbitrary directory paths. This enables reading files with supported extensions such as Python, JavaScript, YAML, and JSON, potentially exposing hard‑coded secrets and credentials. The weakness is classified under CWE‑73, indicating a path traversal or external input containment issue.

Affected Systems

The flaw affects deployments of AsyncFuncAI:deepwiki-open that contain the changes introduced by commit d92819a. Any build of the application that incorporates this commit remains vulnerable, regardless of the surrounding code version. The product is open source and typically deployed on servers that may expose the /ws/chat endpoint to external networks.

Risk and Exploitability

The CVSS score is 8.7, reflecting high severity. An EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Even without an EPSS value, the vulnerability is highly exploitable because it requiresSocket connection to the exposed /ws/chat endpoint. Attacker can craft a payload with a chosen repo_url path to read sensitive files, directly compromising the confidentiality of the system.

Generated by OpenCVE AI on September 15, 2026 at 13:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated release of DeepWiki-Open that removes or fixes the arbitrary file read logic in the /ws/chat endpoint.
  • If an immediate update is not feasible, restrict access to the /ws/chat endpoint so that only authenticated users can connect, effectively blocking unauthenticated file read attempts.
  • Configure firewall or reverse‑proxy rules to limit connections to the WebSocket endpoint to trusted IP ranges or internal networks, reducing the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 13:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Asyncfuncai
Asyncfuncai deepwiki-open
Vendors & Products Asyncfuncai
Asyncfuncai deepwiki-open

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.
Title DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Asyncfuncai Deepwiki-open
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:06.565Z

Reserved: 2026-09-14T11:34:24.687Z

Link: CVE-2026-90946

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:11.991Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:29.180

Modified: 2026-09-23T17:17:44.713

Link: CVE-2026-90946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:30:13Z

Weaknesses
  • CWE-73

    External Control of File Name or Path