Filtered by vendor Asyncfuncai
Subscriptions
Filtered by product Deepwiki-open
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-72567 | 1 Asyncfuncai | 1 Deepwiki-open | 2026-08-11 | 9.8 Critical |
| An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint constructs file paths from user-controlled owner, repo, and repo_type fields without sanitization, enabling path traversal. | ||||
Page 1 of 1.