<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:deepwiki-Open:deepwiki-Open:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adeepwiki-opendeepwiki-open/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 00:37:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adeepwiki-opendeepwiki-open/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Arbitrary File Read in DeepWiki-Open</title><link>https://feed.craftedsignal.io/briefs/2026-10-deepwiki-file-read/</link><pubDate>Thu, 01 Oct 2026 00:37:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-deepwiki-file-read/</guid><description>DeepWiki-Open through commit d92819a is vulnerable to an unauthenticated arbitrary file read via the repo_url parameter in the GET /codemap/file endpoint.</description><content:encoded><![CDATA[<p>DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability. The issue resides in the GET /codemap/file endpoint, which improperly validates the repo_url parameter. By supplying a non-URL value, an attacker can bypass intended path containment checks. This allows for the traversal of the filesystem and the retrieval of sensitive files accessible to the API process. This vulnerability poses a significant risk as it requires no authentication to exploit and provides a mechanism for attackers to exfiltrate configuration files, source code, or system credentials. Defenders should prioritize patching or restricting access to the affected endpoint.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to read arbitrary files from the host system with the privileges of the web application process. This can lead to the exposure of sensitive credentials, environment variables, and internal configuration details, potentially facilitating further system compromise or data exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the official patch or upgrade DeepWiki-Open to a commit post-d92819a.</li>
<li>Restrict network access to the /codemap/file endpoint using a Web Application Firewall or proxy server until the vulnerability is remediated.</li>
<li>Monitor web server logs for GET requests to /codemap/file that contain filesystem path patterns or absolute paths in the repo_url query parameter.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>file-read</category><category>path-traversal</category></item></channel></rss>