CVE-2026-90946 is a high-severity vulnerability in DeepWiki-Open that allows unauthenticated attackers to read arbitrary files with supported extensions, potentially exposing hardcoded secrets and credentials. The vulnerability exists in the unauthenticated /ws/chat WebSocket endpoint, which accepts a repo_url parameter as a filesystem path without proper containment. This allows attackers to supply arbit [truncated]
The CVE-2026-72602 vulnerability is a path traversal issue in AsyncFuncAI deepwiki-open through commit 16f35a0. This allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint, which accepts an absolute filesystem path parameter and returns a directory listing without authentication due to WIKI_AUTH_MODE defaulting to fal [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:29.220Z and has not been modified since then. CVE-2026-72567 is a critical vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0. The vulnerability is caused by improper path validation in the api/api.py wiki-cache endpoint, which constructs file paths from user-controlled owner [truncated]