HIGHVulnerability

CVE-2026-90946

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-90946
signal_observed_at
2026-09-23T22:45:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-14T18:20:29.180
last_modified
2026-09-23T17:17:44.713

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]External Control of File Name or Path

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90946 — Ninja Signal Threat Intelligence | Ninja Signal