PatchSiren cyber security CVE debrief
CVE-2026-72602 AsyncFuncAI CVE debrief
The CVE-2026-72602 vulnerability is a path traversal issue in AsyncFuncAI deepwiki-open through commit 16f35a0. This allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint, which accepts an absolute filesystem path parameter and returns a directory listing without authentication due to WIKI_AUTH_MODE defaulting to false. Organizations should review their deployments and consider patching or mitigating this vulnerability to prevent potential directory listing attacks.
- Vendor
- AsyncFuncAI
- Product
- deepwiki-open
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-28
Who should care
Organizations using AsyncFuncAI deepwiki-open, especially those with publicly exposed instances, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and applying patches, verifying authentication settings, and monitoring for potential exploitation attempts. IT security teams and system administrators responsible for maintaining AsyncFuncAI deepwiki-open deployments should prioritize this vulnerability for remediation due to its high severity and potential impact on directory listings and sensitive data exposure. Additionally, organizations should assess their current configurations, review system logs for suspicious activity, and ensure that compensating controls are in place while remediation is being planned and implemented. This vulnerability may also be of interest to cybersecurity teams performing vulnerability management and penetration testing, as well as compliance officers evaluating the security posture of their organization's systems and data assets. The vulnerability's impact on directory listings and potential for sensitive information disclosure make it a critical concern for organizations relying on AsyncFuncAI deepwiki-open for their operations. Therefore, prompt action is recommended to address this vulnerability and minimize potential risks to the organization's security and data integrity. To further verify the vulnerability, defenders should check for evidence of exploitation in system logs and monitor for unusual activity related to the local-repository structure endpoint. They should also consider implementing additional security measures, such as restricting access to sensitive directories and enhancing monitoring capabilities, to mitigate the risk of exploitation. By taking proactive steps to address this vulnerability, organizations can help protect their systems and data from potential attacks and maintain the security and integrity of their information assets. It's also important for organizations to review their incident response plans and ensure that they are prepared to respond quickly and effectively in the event of a security incident related to this vulnerability. Overall, the CVE-2026-726
Technical summary
The CVE-2026-72602 vulnerability is a path traversal issue in AsyncFuncAI deepwiki-open through commit 16f35a0. This allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint, which accepts an absolute filesystem path parameter and returns a directory listing without authentication due to WIKI_AUTH_MODE defaulting to false.
Defensive priority
Organizations using AsyncFuncAI deepwiki-open should prioritize patching this vulnerability to prevent potential directory listing attacks.
Recommended defensive actions
- Review and apply the patch for AsyncFuncAI deepwiki-open to prevent directory listing attacks.
- Verify that WIKI_AUTH_MODE is set to true to require authentication for accessing the local-repository structure endpoint.
- Monitor for potential exploitation attempts targeting the local-repository structure endpoint.
- Perform an inventory of systems using AsyncFuncAI deepwiki-open to identify potential exposure.
- Implement compensating controls, such as restricting access to sensitive directories, to mitigate the risk of exploitation.
- Review system logs for evidence of exploitation and monitor for unusual activity related to the local-repository structure endpoint.
- Consider rolling back to a previous version or applying additional security measures if patching is not feasible.
Evidence notes
The CVE description indicates a path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0, allowing unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncFuncAI/deepwiki-open
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.