VYPR

deepwiki-open

by AsyncFuncAI

CVEs (2)

  • CVE-2026-72567CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint constructs file paths from user-controlled owner,…

  • CVE-2026-72602HigAug 11, 2026
    risk 0.49cvss 7.5epss

    A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path…