CVE-2026-40518: ByteDance DeerFlow Path Traversal and Arbitrary File Write via Bootstrap Mode
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as the agent name to influence directory creation and write files outside the intended custom-agent directory, potentially achieving arbitrary file write on the system subject to filesystem permissions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40518?
CVE-2026-40518 is categorized as a medium severity vulnerability due to its potential for unauthorized file writes.
How do I fix CVE-2026-40518?
To mitigate CVE-2026-40518, upgrade ByteDance DeerFlow to commit 2176b2b or later where the vulnerability is patched.
What is the impact of CVE-2026-40518?
CVE-2026-40518 allows attackers to exploit path traversal to write arbitrary files, potentially leading to data compromise.
Who is affected by CVE-2026-40518?
Users of ByteDance DeerFlow versions prior to commit 2176b2b are affected by CVE-2026-40518.
What kind of vulnerability is CVE-2026-40518?
CVE-2026-40518 is a path traversal and arbitrary file write vulnerability associated with bootstrap-mode custom-agent creation.