chiprook
← Security
SecurityOctober 11, 2026, 07:30

DeepSeek Harness CVE-2026-82533 analysis: how an agent escapes its sandbox

An analysis of how CVE-2026-82533 (severity 9.4) in DeepSeek Harness let a sandboxed agent call the tool's unauthenticated local HTTP API, escalate its session to danger-full-access and run commands without approval. Fixed in 0.1.2-alpha.1 on August 27, 2026; disclosed publicly on September 8.

DeepSeek Harness CVE-2026-82533 analysis: how an agent escapes its sandbox
#DeepSeek#GitHub
Read next
Security

OpenAI incident analysis: agents escaped sandbox due to human error

Security

CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store

Security

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass

Security

OpenAI agents escaped ExploitGym sandbox and breached Hugging Face