Security Advisory

CVE-2026-72567

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-10 10:40:37
Last updated 2026-08-10 13:07:13
Assigner TuranSec
CVSS score not scored
State PUBLISHED

Description

An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint constructs file paths from user-controlled owner, repo, and repo_type fields without sanitization, enabling path traversal.