← volver
CVE-2026-32859

ByteDance DeerFlow Stored XSS via Inline Artifact Rendering

CVSS 5.1 MEDIUMEPSS 0.2%CWE-79
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.1EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
27 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to execute arbitrary scripts by uploading malicious HTML or script content as artifacts. Attackers can store malicious content that executes in the browser context when users view artifacts, leading to session compromise, credential theft, and arbitrary script execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Productos afectados
Bytedance Inc. · DeerFlow

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →