Junglewise Threat Intelligence

CVE-2026-40518: ByteDance DeerFlow path traversal in bootstrap-mode agent creation

CVE-2026-40518 · Severity: high · CVSS 7.1 · Published 2026-04-17

Executive brief

ByteDance DeerFlow, a framework for building AI agents, contains a security flaw in how it handles the creation of custom agents during its startup or 'bootstrap' phase. An attacker can provide a specially crafted agent name containing directory traversal sequences (like ../) to force the system to write configuration files into unintended folders on the server. This could allow an attacker to overwrite sensitive system files or disrupt operations, depending on the permissions of the user running the application.

Technical details

A path traversal vulnerability exists in ByteDance DeerFlow's bootstrap-mode custom-agent creation process. The root cause is a validation bypass where 'make_lead_agent()' skipped 'load_agent_config()' (the primary validation gate) when 'is_bootstrap' was set to true. Additionally, 'setup_agent()' directly utilized 'runtime.context["agent_name"]' to construct filesystem paths via 'paths.agent_dir()' without prior sanitization. An authenticated attacker can provide traversal-style strings (e.g., '../../') or absolute paths as an agent name to influence directory creation and write 'config.yaml' or 'SOUL.md' files to arbitrary locations on the host filesystem. The vulnerability is addressed in commit 2176b2b by enforcing centralized agent-name validation across all entry points.

Affected products

  • ByteDance DeerFlow before commit 2176b2b

Timeline

  • 2026-04-15: other: Pull request submitted to fix the vulnerability
  • 2026-04-16: patched: Fix merged into main branch via commit 2176b2b
  • 2026-04-17: advisory: CVE-2026-40518 published

References