GHSA-76gj-49mh-j4cfHighCVSS 7.5

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the...

Published
September 14, 2026
Last Modified
September 14, 2026

🔗 CVE IDs covered (1)

📋 Description

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.

🔗 References (7)