Executive brief
AsyncFuncAI deepwiki-open is an AI-powered wiki generator that indexes and documents code repositories. A path traversal vulnerability in its local-repository endpoint allows unauthenticated attackers to list the contents of arbitrary directories on the host system, potentially exposing sensitive configuration files, credentials, and system information that could be leveraged for further attacks.
Technical details
The vulnerability is a path traversal flaw in the local-repository structure endpoint that fails to validate or sanitize filesystem path parameters. The endpoint accepts absolute filesystem paths and returns directory listings without requiring authentication, as the WIKI_AUTH_MODE setting defaults to false. An attacker can enumerate arbitrary directories on the server by crafting requests with different path parameters, gaining visibility into the filesystem layout and potentially discovering sensitive files. The vulnerability is reachable over the network without authentication and requires no user interaction. No patch information is currently available as of the advisory publication date.
Affected products
- AsyncFuncAI deepwiki-open through commit 16f35a0
Timeline
- 2026-08-11: disclosed