CVE-2026-103591: DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repourl parameter. Attackers can supply a non-URL repourl value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated network client that can reach the GET /codemap/file endpoint can attempt exploitation. No privileges or user interaction are required.
What access can an attacker gain?
An attacker can read arbitrary files that are accessible to the API process. The issue affects confidentiality; the supplied data does not indicate file modification or service disruption.
What input is required to exploit it?
The attacker supplies a non-URL value in the repo_url parameter to bypass the endpoint's path-containment checks, then specifies an absolute file path.
How can I determine whether my deployment is affected?
Deployments of DeepWiki-Open through commit d92819a are identified as affected. Check whether the exposed API includes GET /codemap/file and whether its code corresponds to or predates that commit.