Junglewise Threat Intelligence

CVE-2026-32859: ByteDance DeerFlow stored XSS in artifacts API

CVE-2026-32859 · Severity: medium · CVSS 5.4 · Published 2026-03-27

Executive brief

ByteDance DeerFlow, a workflow automation tool, is vulnerable to a security flaw where malicious files can be uploaded and executed in a user's browser. An attacker could use this to steal login credentials or take over user sessions when a victim views a compromised file. This issue has been resolved in recent updates by forcing these files to download rather than opening them directly in the browser.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the DeerFlow artifacts API due to improper handling of active MIME types. The application previously allowed active web content (such as HTML, XHTML, and SVG) to be rendered inline in the browser. An authenticated attacker can upload a malicious artifact that, when viewed by another user, executes arbitrary JavaScript in the context of the application's domain. This can lead to session hijacking and credential theft. The vulnerability was addressed by modifying the gateway to enforce 'Content-Disposition: attachment' for active MIME types, ensuring they are downloaded rather than rendered inline.

Affected products

  • ByteDance DeerFlow versions prior to commit 5dbb3623b2f0e490c8bb3cd81b1e3b1b12eae1a6

Timeline

  • 2026-03-26: patched: Fix merged in pull request #1389
  • 2026-03-27: disclosed: Initial NVD publication

References