在提交 d92819a 之前的 DeepWiki-Open 存在一个任意文件读取漏洞,位于未鉴权的 WebSocket 端点。该端点接受 作为文件系统路径,但未做路径限制(no containment)。攻击者可以传入任意目录路径,从而读取所有受支持扩展名的文件,包括包含硬编码密钥和凭据的 Python、JavaScript、YAML 和 JSON 文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AsyncFuncAI | deepwiki-open | ≤ d92819a |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AsyncFuncAI | deepwiki-open | 0 ~ d92819a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet