CVE-2026-103591
Deferred Deferred - Pending Action

Unauthenticated Arbitrary File Read in DeepWiki-Open

Vulnerability report for CVE-2026-103591, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated arbitrary file read issue in DeepWiki-Open. It exists in the GET /codemap/file endpoint where the repo_url parameter is not properly validated. Attackers can bypass path checks by providing non-URL values and read any file accessible to the API process using absolute file paths.

Detection Guidance

To detect this vulnerability, check if the DeepWiki-Open API is running and test the /codemap/file endpoint with a non-URL repo_url parameter. Use curl commands like: curl -v 'http://target/codemap/file?repo_url=file:///etc/passwd' to see if arbitrary files are returned.

Impact Analysis

An attacker could exploit this to read sensitive files on the server, including configuration files, source code, or other confidential data. This could lead to further attacks like data theft, privilege escalation, or system compromise depending on the exposed files.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately update DeepWiki-Open to a version beyond commit d92819a. If an update is not available, restrict access to the /codemap/file endpoint or implement strict input validation for the repo_url parameter to prevent path traversal.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103591. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart