


Perceptive Security
SOC/SIEM Consultancy

ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agen…
Published:
16 April 2026 at 22:00:00
Alert date:
17 April 2026 at 20:03:43
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
ByteDance DeerFlow contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation. The vulnerability exists before commit 2176b2b where agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as the agent name to influence directory creation. This allows writing files outside the intended custom-agent directory. The vulnerability potentially enables arbitrary file write on the system subject to filesystem permissions. The issue has been addressed in the specified commit.
Technical details
Mitigation steps:
Affected products:
ByteDance DeerFlow
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40518
https://github.com/bytedance/deer-flow/commit/2176b2bbfccfce25ceee08318813f96d843a13fd
https://github.com/bytedance/deer-flow/pull/2274
https://www.vulncheck.com/advisories/bytedance-deerflow-path-traversal-and-arbitrary-file-write-via-bootstrap-mode
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
