Path Traversal Vulnerability in AsyncFuncAI DeepWiki-Open
CVE-2026-72602
7.5HIGH
What is CVE-2026-72602?
An identified path traversal vulnerability in AsyncFuncAI's DeepWiki-Open allows unauthorized users to exploit the local-repository structure endpoint. This security flaw occurs because the endpoint permits the use of an absolute filesystem path parameter, leading to the retrieval of sensitive directory listings without authentication. With the WIKI_AUTH_MODE setting defaulting to false, malicious actors can enumerate confidential directory contents on the host system, raising significant security concerns for affected users.
Affected Version(s)
deepwiki-open 0 <= 16f35a0
