What is CVE-2026-72567?
CVE-2026-72567 is a critical vulnerability in the AsyncFuncAI/deepwiki-open platform. It allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges due to improper path validation. The flaw exists in the `/api/wiki-cache` endpoint, which constructs file paths from user-controlled `owner`, `repo`, and `repo_type` parameters without proper sanitization.
Azərbaycanca: CVE-2026-72567, AsyncFuncAI/deepwiki-open platformunda aşkar edilmiş ciddi bir zəiflikdir. Bu boşluq autentifikasiya olmamış uzaq hücumçulara root səlahiyyətləri ilə ixtiyari faylları yazmağa və ya silməyə imkan verir. Zəiflik `/api/wiki-cache` endpointində istifadəçi tərəfindən idarə olunan `owner`, `repo` və `repo_type` parametrlərindən fayl yolu qurarkən düzgün yoxlamanın aparılmamasından qaynaqlanır.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
What privileges does an attacker have when exploiting the CVE-2026-72567 vulnerability in the AsyncFuncAI/deepwiki-open platform?
The attacker can write to or delete arbitrary files with root privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.