Product
DeepWiki-Open through commit d92819a is vulnerable to an unauthenticated arbitrary file read via the repo_url parameter in the GET /codemap/file endpoint.