Loading market data...
← Back to CVE feed

CVE-2026-103591

HIGH CVSS 7.5 View on NVD ↗

Description

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Sep 30, 2026 23:16 UTC Modified: Sep 30, 2026 23:16 UTC