CVE-2026-103591 - DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file
CVE ID :CVE-2026-103591
Published : Sept. 30, 2026, 11:16 p.m. | 1 hour, 56 minutes ago
Description :DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 30, 2026, 11:16 p.m. | 1 hour, 56 minutes ago
Description :DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...