Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103591— DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file

Quick assessment

Affected
AsyncFuncAI deepwiki-open
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DeepWiki-Open 在提交 d92819a 及之前版本中存在一个未经身份验证的任意文件读取漏洞,该漏洞存在于 GET /codemap/file 端点中,可通过 repo_url 参数利用。攻击者可以提供一个非 URL 格式的 repo_url 值来绕过路径包含检查,并通过指定绝对文件路径读取 API 进程可访问的任意文件。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103591

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file
Source: CVE Program / CVE List V5
Vulnerability Description
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
AsyncFuncAI deepwiki-open 0 ~ d92819a -

II. Public POCs for CVE-2026-103591

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103591

请登录查看更多情报信息。

Other References for CVE-2026-103591 (1)

Other References for CVE-2026-103591 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-103591

No comments yet


Leave a comment