CVE-2026-90946
Last modified
CVE-2026-90946 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials..
Description
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AsyncFuncAI | deepwiki-open | <= d92819a |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90946?
How severe is CVE-2026-90946?
How do I fix CVE-2026-90946?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90940novel-plus through 5.3.3 contains an insecure default cache-…5.3
- CVE-2026-90941novel-plus through 5.3.3 contains an authorization bypass vu…4.3
- CVE-2026-90942Casdoor through 4.4.0 fails to properly mask the instance-wi…9.6
- CVE-2026-90943parallax filament-comments through 3.0.0 contains a stored c…8.7
- CVE-2026-90944Krayin CRM through 2.2.6 exposes the POST /admin/mail/inboun…8.2
- CVE-2026-90945Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret f…9.8
- CVE-2026-90947A flaw was found in GIMP. When processing a specially crafte…7.8
- CVE-2026-90948A flaw was found in GIMP's ICO file loader. When processing …7.8
- CVE-2026-90949A flaw was found in GIMP's PSP (Paint Shop Pro) file loader.…7.8
- CVE-2026-9095Casdoor versions 2.362.0 and earlier map SAML assertions to …8.1
- CVE-2026-90955Affected versions of MISP’s interactive CLI shell do not rel…4.6
- CVE-2026-90957Affected versions of MISP serve uploaded SVG images inline w…5.1
Are you affected by CVE-2026-90946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
