Security Advisory

CVE-2026-90946

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-14 17:52:06
Last updated 2026-09-14 18:09:27
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.