PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72602 AsyncFuncAI CVE debrief

The CVE-2026-72602 vulnerability is a path traversal issue in AsyncFuncAI deepwiki-open through commit 16f35a0. This allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint, which accepts an absolute filesystem path parameter and returns a directory listing without authentication due to WIKI_AUTH_MODE defaulting to false. Organizations should review their deployments and consider patching or mitigating this vulnerability to prevent potential directory listing attacks.

Vendor
AsyncFuncAI
Product
deepwiki-open
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-08-28
Advisory published
2026-08-11
Advisory updated
2026-08-28

Who should care

Organizations using AsyncFuncAI deepwiki-open, especially those with publicly exposed instances, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and applying patches, verifying authentication settings, and monitoring for potential exploitation attempts. IT security teams and system administrators responsible for maintaining AsyncFuncAI deepwiki-open deployments should prioritize this vulnerability for remediation due to its high severity and potential impact on directory listings and sensitive data exposure. Additionally, organizations should assess their current configurations, review system logs for suspicious activity, and ensure that compensating controls are in place while remediation is being planned and implemented. This vulnerability may also be of interest to cybersecurity teams performing vulnerability management and penetration testing, as well as compliance officers evaluating the security posture of their organization's systems and data assets. The vulnerability's impact on directory listings and potential for sensitive information disclosure make it a critical concern for organizations relying on AsyncFuncAI deepwiki-open for their operations. Therefore, prompt action is recommended to address this vulnerability and minimize potential risks to the organization's security and data integrity. To further verify the vulnerability, defenders should check for evidence of exploitation in system logs and monitor for unusual activity related to the local-repository structure endpoint. They should also consider implementing additional security measures, such as restricting access to sensitive directories and enhancing monitoring capabilities, to mitigate the risk of exploitation. By taking proactive steps to address this vulnerability, organizations can help protect their systems and data from potential attacks and maintain the security and integrity of their information assets. It's also important for organizations to review their incident response plans and ensure that they are prepared to respond quickly and effectively in the event of a security incident related to this vulnerability. Overall, the CVE-2026-726

Technical summary

The CVE-2026-72602 vulnerability is a path traversal issue in AsyncFuncAI deepwiki-open through commit 16f35a0. This allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint, which accepts an absolute filesystem path parameter and returns a directory listing without authentication due to WIKI_AUTH_MODE defaulting to false.

Defensive priority

Organizations using AsyncFuncAI deepwiki-open should prioritize patching this vulnerability to prevent potential directory listing attacks.

Recommended defensive actions

  • Review and apply the patch for AsyncFuncAI deepwiki-open to prevent directory listing attacks.
  • Verify that WIKI_AUTH_MODE is set to true to require authentication for accessing the local-repository structure endpoint.
  • Monitor for potential exploitation attempts targeting the local-repository structure endpoint.
  • Perform an inventory of systems using AsyncFuncAI deepwiki-open to identify potential exposure.
  • Implement compensating controls, such as restricting access to sensitive directories, to mitigate the risk of exploitation.
  • Review system logs for evidence of exploitation and monitor for unusual activity related to the local-repository structure endpoint.
  • Consider rolling back to a previous version or applying additional security measures if patching is not feasible.

Evidence notes

The CVE description indicates a path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0, allowing unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72602 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72602

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72602 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72602

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncFuncAI/deepwiki-open

    309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.