MEDIUM SEVERITYCONFIRMED
str_replace_tool returns OK for empty files without checking old_str
Package
DeerFlow
Version
latest
Verified
2026-03-28
Description
DeerFlow's `str_replace_tool` at `tools.py:879` has an early return: `if not content: return 'OK'`. This bypasses the 'old_str not found' check for empty files, returning success even when the intended replacement string was not present.
Reproduction
# tools.py:879:
if not content:
return 'OK' # Bypasses the not-found check entirely