216.73.216.233

CVE-2026-34430

· Published 01/04/2026 14:16 · Modified 02/04/2026 19:41

Labels: CVE-2026-34430 2026-04-01CVE-2026-34430CWE-184NVD-CWE-noinfo[email protected]

Essential information

Published
01/04/2026 14:16
Modified
02/04/2026 19:41
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

ByteDance Deer-Flow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox boundary and achieve arbitrary command execution through subprocess invocation with shell interpretation enabled.

NVD status

Status
Analyzed — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
deerflow / deerflow cpe:2.3:a:deerflow:deerflow:*:*:*:*:*:*:*:*

References