Skip to content
Threat Feed
high advisory

Unauthenticated Arbitrary File Read in DeepWiki-Open

DeepWiki-Open through commit d92819a is vulnerable to an unauthenticated arbitrary file read via the repo_url parameter in the GET /codemap/file endpoint.

CVE search metadata

CVE search record: CVE-2026-103591. Severity: high. CVSS: 7.5. KEV: no. Product: DeepWiki-Open (<= d92819a). Brief: Unauthenticated Arbitrary File Read in DeepWiki-Open. Brief link: https://feed.craftedsignal.io/briefs/2026-10-deepwiki-file-read/

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability. The issue resides in the GET /codemap/file endpoint, which improperly validates the repo_url parameter. By supplying a non-URL value, an attacker can bypass intended path containment checks. This allows for the traversal of the filesystem and the retrieval of sensitive files accessible to the API process. This vulnerability poses a significant risk as it requires no authentication to exploit and provides a mechanism for attackers to exfiltrate configuration files, source code, or system credentials. Defenders should prioritize patching or restricting access to the affected endpoint.

Impact

Successful exploitation allows unauthenticated attackers to read arbitrary files from the host system with the privileges of the web application process. This can lead to the exposure of sensitive credentials, environment variables, and internal configuration details, potentially facilitating further system compromise or data exfiltration.

Recommendation

  • Apply the official patch or upgrade DeepWiki-Open to a commit post-d92819a.
  • Restrict network access to the /codemap/file endpoint using a Web Application Firewall or proxy server until the vulnerability is remediated.
  • Monitor web server logs for GET requests to /codemap/file that contain filesystem path patterns or absolute paths in the repo_url query parameter.

Immediate actions

Upgrade DeepWiki-Open beyond commit d92819a

IT Operations 72h

Threat Hunt

Search logs for unusual repo_url values in /codemap/file requests

T1083 high high confidence hunt now

Data: webserver_logs

Detection coverage 1

Detect CVE-2026-103591 Exploitation - Arbitrary File Read

high

Detects potential exploitation of CVE-2026-103591 by monitoring for absolute file paths or directory traversal patterns within the repo_url parameter of the /codemap/file endpoint.

sigma tactics: initial_access techniques: T1083 sources: webserver

Detection queries are available on the platform. Get full rules →