PT-2026-28445 · Bytedance · Deer-Flow
Published
2026-03-27
·
Updated
2026-05-12
·
CVE-2026-32859
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ByteDance Deer-Flow versions prior to commit 5dbb362
Description
The software contains a stored cross-site scripting issue in the artifacts API. An attacker can execute arbitrary scripts by uploading malicious HTML or script content as artifacts. When users view these artifacts, malicious content executes in the browser, potentially leading to session compromise and credential theft. The vulnerability allows for arbitrary script execution.
Recommendations
Update to version 5dbb362 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deer-Flow