


Perceptive Security
SOC/SIEM Consultancy

ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agen…
Published:
16 april 2026 om 22:00:00
Alert date:
17 april 2026 om 18:01:51
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
ByteDance DeerFlow contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation. The vulnerability exists before commit 2176b2b where agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as agent names to influence directory creation. This allows writing files outside the intended custom-agent directory. The vulnerability can potentially achieve arbitrary file write on the system subject to filesystem permissions. The issue affects the custom-agent creation functionality specifically.
Technical details
Mitigation steps:
Affected products:
ByteDance DeerFlow
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40518
https://github.com/bytedance/deer-flow/commit/2176b2bbfccfce25ceee08318813f96d843a13fd
https://github.com/bytedance/deer-flow/pull/2274
https://www.vulncheck.com/advisories/bytedance-deerflow-path-traversal-and-arbitrary-file-write-via-bootstrap-mode
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
