CVE-2026-34430
Last modified
CVE-2026-34430 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox boundary and achieve arbitrary command execution through subprocess invocation with shell interpretation enabled.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox boundary and achieve arbitrary command execution through subprocess invocation with shell interpretation enabled.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Deerflow | Deerflow | < 2026-03-29 |
References
- https://github.com/bytedance/deer-flow/pull/1547Issue Tracking, Patch, Vendor Advisory
- https://www.vulncheck.com/advisories/bytedance-deerflow-localsandboxprovider-host-bash-escapeThird Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-34430?
How severe is CVE-2026-34430?
How do I fix CVE-2026-34430?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34424Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla…9.8
- CVE-2026-34425OpenClaw versions prior to commit 8aceaf5 contain a prefligh…4.3
- CVE-2026-34426OpenClaw versions prior to commit b57b680 contain an approva…7.3
- CVE-2026-34427Vvveb prior to 1.0.8.1 contains a privilege escalation vulne…8.8
- CVE-2026-34428Vvveb prior to 1.0.8.1 contains a server-side request forger…8.3
- CVE-2026-34429Vvveb prior to 1.0.8.1 contains a stored cross-site scriptin…5.4
- CVE-2026-34441cpp-httplib is a C++11 single-file header-only cross platfor…6.5
- CVE-2026-34442FreeScout is a free help desk and shared inbox built with PH…6.1
- CVE-2026-34443FreeScout is a free help desk and shared inbox built with PH…5.3
- CVE-2026-34444Lupa integrates the runtimes of Lua or LuaJIT2 into CPython.…10
- CVE-2026-34445Open Neural Network Exchange (ONNX) is an open standard for …8.6
- CVE-2026-34446Open Neural Network Exchange (ONNX) is an open standard for …5.5
Are you affected by CVE-2026-34430?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
