CVE-2026-90946 | AsyncFuncAI DeepWiki-Open WebSocket Endpoint /ws/chat repo_url path traversal (d92819a)
A vulnerability marked as problematic has been reported in AsyncFuncAI DeepWiki-Open. This vulnerability affects unknown code of the file /ws/chat of the component WebSocket Endpoint. Performing a manipulation of the argument repo_url results in path traversal.
This vulnerability is cataloged as CVE-2026-90946. It is possible to initiate the attack remotely. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More