ZeroHour
Product

DeepSeek Harness

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

DeepSeek Harness (CVE-2026-82533, CVSS 9.4) let AI coding agents disable their own sandbox via an unauthenticated local API; fixed in 0.1.2-alpha.2.

DeepSeek Harness versions 0.1.1-rc.2 and earlier allowed a sandboxed AI coding agent to turn off its own OS sandbox by calling the tool's unauthenticated local web interface, tracked as CVE-2026-82533 with a 9.4 CVSS from VulnCheck. A single command set the agent session to danger-full-access mode, removing sandboxing and approval prompts, and OX Research verified writes escaped the workspace. The interface trusted the client-supplied Host header with no authentication and could also return a session's entire conversation log. The fix adds a one-time token and signed-cookie check; the first npm release carrying it is 0.1.2-alpha.2, with 0.1.2-rc.1 current.

The Hacker News · 6d agoAI safety & security in the wildCVE-2026-82533

Related CVEs

  • Host Header Authentication Bypass in DeepSeek Harness Local Control-Plane API
    DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass (CWE-807) in its local HTTP control-plane API: the server decides whether a request is trusted based only on the client-supplied Host header instead of verifying the actual origin of the TCP connection. An attacker who sends a request with a spoofed, accepted Host value is treated as a trusted local client and requires no credential or API key; the CVSS 4.0 vector's user-interaction flag (UI:P) suggests exploitation likely involves some user-triggered request reaching the API. With this access the attacker gains full agent control, including invoking privileged commands such as commands/execute with danger-full-access permissions, escalating the session approval policy to unconfined execution (so the AI agent can disable its own file sandbox without approval), and reading all stored conversations. Anyone running an affected version of DeepSeek Harness is exposed, with the local control-plane API as the attack surface. No public proof of concept or in-the-wild exploitation is known, the issue is not in CISA KEV, and EPSS estimates a roughly 0.4% chance of exploitation within 30 days (35th percentile), but the critical 9.4 CVSS 4.0 score warrants prompt patching.
    · DeepSeek Harness all versions before 0.1.2-alpha.1niche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.