ByteDance DeerFlow versions prior to commit 2176b2b contain a critical path traversal and arbitrary file write vulnerability in the bootstrap-mode custom-agent creation function. An inadequate agent name validation allows attackers to bypass security controls by supplying directory traversal sequences or absolute paths, enabling unauthorized file writes outside the intended custom-agent directory and potentially compromising system integrity depending on filesystem permissions. The vulnerability presents a high-severity risk with a CVSS score of 7.1, requiring low attack complexity and only basic user authentication to exploit remotely. While the attack does not directly compromise confidentiality, it carries significant integrity and availability impacts, as attackers can write arbitrary files to critical system locations and potentially disrupt service operations. There is currently no evidence of active exploitation in the wild, as the vulnerability is not tracked on CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.0003 indicates exceptionally low empirical probability of near-term exploitation, and the vulnerability remains inactive on security hotlists, suggesting limited community attention at this time. Organizations running affected ByteDance DeerFlow instances should prioritize patching to the fixed commit 2176b2b to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0-m0CPE matchmatch criteria | cpe:2.3:a:bytedance:deerflow:2.0-m0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.