Impact
DeepWiki-Open includes an arbitrary file read flaw in its unauthenticated /ws/chat WebSocket endpoint. The endpoint accepts a repo_url parameter that is interpreted as a filesystem path without any containment checks, allowing an attacker to supply arbitrary directory paths. This enables reading files with supported extensions such as Python, JavaScript, YAML, and JSON, potentially exposing hard‑coded secrets and credentials. The weakness is classified under CWE‑73, indicating a path traversal or external input containment issue.
Affected Systems
The flaw affects deployments of AsyncFuncAI:deepwiki-open that contain the changes introduced by commit d92819a. Any build of the application that incorporates this commit remains vulnerable, regardless of the surrounding code version. The product is open source and typically deployed on servers that may expose the /ws/chat endpoint to external networks.
Risk and Exploitability
The CVSS score is 8.7, reflecting high severity. An EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Even without an EPSS value, the vulnerability is highly exploitable because it requiresSocket connection to the exposed /ws/chat endpoint. Attacker can craft a payload with a chosen repo_url path to read sensitive files, directly compromising the confidentiality of the system.
OpenCVE Enrichment