01 Record
CVE-2026-90946
DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket
HighPUBLISHEDCNA: VulnCheck
CNA base score8.7 CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
02 Description
DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket
03 Exploitation and scoring
- Exploitation
- Public exploit code exists. CISA's assessment records a public proof of concept. That is not a report of exploitation in the wild.
- SSVC decision
- ExploitationpocPublic proof-of-concept exploit code exists. Not a report of exploitation in the wild.
- AutomatableyesAn attacker can reliably automate reconnaissance through exploitation, so this scales.
- Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
- EPSS probability
- Not scored by EPSS
- EPSS percentile
- Not scored by EPSS
- NVD base score
- The NVD has published no score for this record
- NVD CVSS vector
- No NVD score to derive
- NVD analysis status
- Not recorded
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
04 Metadata
- Published
- 2026-09-14 17:52Z1 HR AGO
- Last updated
- 2026-09-14 18:09Z51 MIN AGO
- Reserved
- 2026-09-14
- Assigning CNA
- VulnCheck
- Record state
- PUBLISHED
- Severity
- High (CVSS 8.7)
- CNA CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- Weaknesses
- CWE-73External Control of File Name or PathBase
- Data version
- 5.2
- Document digest
- 05726456073c11600fe6ca13a86d105225a9e72b7e33d885d0bd95e1e4d83019
05 Affected products
VendorProductVersionsPlatforms
06 References
- github.comGitHub Issue #536https://github.com/AsyncFuncAI/deepwiki-open/issues/536
- github.comhttps://github.com/AsyncFuncAI/deepwiki-open
- github.comapi/data_pipeline.py at 16f35a0https://github.com/AsyncFuncAI/deepwiki-open/blob/16f35a0fc0284e99b7963bbf4e8585e9957e2fe1/api/data_pipeline.py
- github.comapi/repository.py at d92819ahttps://github.com/AsyncFuncAI/deepwiki-open/blob/d92819a9c9f3b99416e3580ff235fc9d3adf8b89/api/repository.py
- www.vulncheck.comVulnCheck Advisory: DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSockethttps://www.vulncheck.com/advisories/deepwiki-open-through-commit-d92819a-arbitrary-file-read-via-ws-chat-websocket