synced 14 MIN AGO
01 Record

CVE-2026-90946

DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket

HighPUBLISHEDCNA: VulnCheck
CNA base score8.7 CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

02 Description

DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket

03 Exploitation and scoring

Exploitation
Public exploit code exists. CISA's assessment records a public proof of concept. That is not a report of exploitation in the wild.
SSVC decision
  • ExploitationpocPublic proof-of-concept exploit code exists. Not a report of exploitation in the wild.
  • AutomatableyesAn attacker can reliably automate reconnaissance through exploitation, so this scales.
  • Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.
EPSS probability
Not scored by EPSS
EPSS percentile
Not scored by EPSS
NVD base score
The NVD has published no score for this record
NVD CVSS vector
No NVD score to derive
NVD analysis status
Not recorded
Red Hat severity
No Red Hat rating. Red Hat rates the CVEs that affect its products.

Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.

04 Metadata

Published
2026-09-14 17:52Z1 HR AGO
Last updated
2026-09-14 18:09Z51 MIN AGO
Reserved
2026-09-14
Assigning CNA
VulnCheck
Record state
PUBLISHED
Severity
High (CVSS 8.7)
CNA CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Weaknesses
  • CWE-73External Control of File Name or PathBase
Data version
5.2
Document digest
05726456073c11600fe6ca13a86d105225a9e72b7e33d885d0bd95e1e4d83019

05 Affected products

VendorProductVersionsPlatforms
AsyncFuncAIdeepwiki-open0 to d92819a

06 References