CVE-2026-32859: ByteDance DeerFlow Stored XSS via Inline Artifact Rendering
ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to execute arbitrary scripts by uploading malicious HTML or script content as artifacts. Attackers can store malicious content that executes in the browser context when users view artifacts, leading to session compromise, credential theft, and arbitrary script execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ByteDance DeerFlowto a version that resolves this vulnerability.Patch 5dbb362
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32859?
The severity of CVE-2026-32859 is classified as high due to its potential impact allowing attackers to execute arbitrary scripts.
How do I fix CVE-2026-32859?
To fix CVE-2026-32859, upgrade to ByteDance Deer-Flow version 5dbb362 or later, which addresses the stored XSS vulnerability.
What does CVE-2026-32859 affect?
CVE-2026-32859 affects all ByteDance Deer-Flow versions prior to commit 5dbb362.
What type of vulnerability is CVE-2026-32859?
CVE-2026-32859 is a stored cross-site scripting (XSS) vulnerability.
What are the risks associated with CVE-2026-32859?
The risks associated with CVE-2026-32859 include potential data theft, user session hijacking, or the execution of malicious scripts in a user's browser.