DeepSeek Harness CVE-2026-82533: sandboxed AI agent disables own sandbox (CVSS 9.4)
OX Research (8 September 2026) and VulnCheck advisory: CVE-2026-82533 (CWE-807) in DeepSeek Harness (dsh) before 0.1.2-alpha.1. The local agent-control HTTP API trusted only the client-supplied Host header, not the TCP peer. The OS sandbox confined file writes but left loopback networking open, so a sandboxed agent could curl the API, set danger-full-access / approval never, and run unconfined — on shipped defaults, with no credentials. If the port was reachable via tunnel/proxy/SSH forward, an unauthenticated remote attacker could control the agent and export stored conversations. CVSS 4.0 9.4 (AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Disclosed to VulnCheck CNA 24 Aug; fixed in 0.1.2-alpha.1 (27 Aug); CVE published 8 Sep. npm package @deepseek-ai/dsh — install 0.1.2-alpha.2+ / current rc. Primary: OX Research; also VulnCheck / THN.
- Product
- DeepSeek Harness (dsh) / @deepseek-ai/dsh
- Versions
- Affected: 0.1.1-rc.2 and earlier; fixed: 0.1.2-alpha.1 and later (npm current 0.1.2-rc.1 per THN 9 Sep)
- CVSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H- Exploited in Australia?
- unknown
- Patch to
- Upgrade DeepSeek Harness to 0.1.2-alpha.1 or later; check third-party desktop wrappers for shipped harness version; avoid exposing the local control port
Primary: OX Research — CVE-2026-82533 DeepSeek Harness (8 Sep 2026) · Vendor: VulnCheck advisory (CNA) · CVE: CVE-2026-82533 · The Hacker News (9 Sep 2026)
