PatchSiren

AsyncFuncAI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL AsyncFuncAI CVE published 2026-08-10

CVE-2026-72567

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:29.220Z and has not been modified since then. CVE-2026-72567 is a critical vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0. The vulnerability is caused by improper path validation in the api/api.py wiki-cache endpoint, which constructs file paths from user-controlled owner [truncated]