PT-2026-70146 · Asyncfuncai · Deepwiki-Open

·

CVE-2026-72602

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AsyncFuncAI deepwiki-open versions prior to commit 16f35a0
Description A path traversal issue allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths. This occurs via the 'local-repository structure' endpoint, which accepts an absolute filesystem path parameter and returns directory listings because WIKI AUTH MODE defaults to false. Path traversal is a flaw that allows an attacker to access files or directories outside the intended folder by using special characters like dot-dot-slash (../).
Recommendations Update AsyncFuncAI deepwiki-open to a version beyond commit 16f35a0. Enable WIKI AUTH MODE to restrict unauthenticated access to the 'local-repository structure' endpoint.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72602

Affected Products

Deepwiki-Open