A vulnerability, which was classified as problematic, was found in Bytedance DeerFlow. This affects an unknown part of the component Artifacts API. Such manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2026-32859. The attack may be launched remotely. There is no exploit available.

It is best practice to apply a patch to resolve this issue.