Unauthenticated Arbitrary File Read in DeepWiki-Open
DeepWiki-Open through commit d92819a is vulnerable to an unauthenticated arbitrary file read via the repo_url parameter in the GET /codemap/file endpoint.
CVE search metadata
CVE search record: CVE-2026-103591. Severity: high. CVSS: 7.5. KEV: no. Product: DeepWiki-Open (<= d92819a). Brief: Unauthenticated Arbitrary File Read in DeepWiki-Open. Brief link: https://feed.craftedsignal.io/briefs/2026-10-deepwiki-file-read/
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability. The issue resides in the GET /codemap/file endpoint, which improperly validates the repo_url parameter. By supplying a non-URL value, an attacker can bypass intended path containment checks. This allows for the traversal of the filesystem and the retrieval of sensitive files accessible to the API process. This vulnerability poses a significant risk as it requires no authentication to exploit and provides a mechanism for attackers to exfiltrate configuration files, source code, or system credentials. Defenders should prioritize patching or restricting access to the affected endpoint.
Impact
Successful exploitation allows unauthenticated attackers to read arbitrary files from the host system with the privileges of the web application process. This can lead to the exposure of sensitive credentials, environment variables, and internal configuration details, potentially facilitating further system compromise or data exfiltration.
Recommendation
- Apply the official patch or upgrade DeepWiki-Open to a commit post-d92819a.
- Restrict network access to the /codemap/file endpoint using a Web Application Firewall or proxy server until the vulnerability is remediated.
- Monitor web server logs for GET requests to /codemap/file that contain filesystem path patterns or absolute paths in the repo_url query parameter.
Immediate actions
Upgrade DeepWiki-Open beyond commit d92819a
Threat Hunt
Search logs for unusual repo_url values in /codemap/file requests
Data: webserver_logs
Detection coverage 1
Detect CVE-2026-103591 Exploitation - Arbitrary File Read
highDetects potential exploitation of CVE-2026-103591 by monitoring for absolute file paths or directory traversal patterns within the repo_url parameter of the /codemap/file endpoint.
Detection queries are available on the platform. Get full rules →