CVE-2026-34430
HIGH 8.8ByteDance Deer-Flow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox boundary and achieve arbitrary command execution through subprocess invocation with shell interpretation enabled.
Affected Applications in Environment
8
Flow
v2.0.143.0
130 devices
Flow
v2.0.137.0
2 devices
Flow
v1.3.173.0
7 devices
Flow
v1.3.176.0
9 devices
Flow
v1.3.51.1
1 device
Flow
v1.3.51.0
2 devices
Flow
v1.3.174.0
1 device
Flow
v2.0.148.0
1 device
Affected Devices
152
118B-13
Windows
118B-14
Windows
118B-15
Windows
118B-18
Windows
DESKTOP-2F2IHK3
Windows
DESKTOP-PIEDSC2
Windows
DPADVS-L72018DT
Windows
DPADVS-L72115D7
Windows
DPAGNF-A7412369
Windows
DPAGNF-A741236B
Windows
DPAGNF-A805193T
Windows
DPATHL-835405G
Windows
DPATHL-83540MD
Windows
DPBIOL-MITZI
Windows
DPCDIS-R90ZC0S3
Windows
DPCHEM-5VDSTNE
Windows
DPELED-D81938YB
Windows
DPEMAE-92503DF
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-07
Windows
DPITED-L240-07
Windows
DPITED-L240-07
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-16
Windows
DPITED-L240-16
Windows
DPITED-L240-16
Windows
DPITED-L240-16
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
FACHVAC-HP640-2
Windows
FACHVAC-HP640-4
Windows
FACHVAC-HP640-5
Windows
FACHVAC92505LP
Windows
HDFS-MXL9273YJB
Windows
HRU5
Windows
HRU6
Windows
HSWENSON
Windows
KRANDOLPH
Windows