DeepSeek Harness CVE-2026-82533 analysis: how an agent escapes its sandbox
An analysis of how CVE-2026-82533 (severity 9.4) in DeepSeek Harness let a sandboxed agent call the tool's unauthenticated local HTTP API, escalate its session to danger-full-access and run commands without approval. Fixed in 0.1.2-alpha.1 on August 27, 2026; disclosed publicly on September 8.
- CVE-2026-82533 rated 9.4: local HTTP API with no auth and Host-header trust
- Sandboxed agent escalated to danger-full-access and disabled approval prompts
- Fixed in 0.1.2-alpha.1 on August 27; public disclosure on September 8, 2026
- DeepSeek Harness: 246,721 GitHub stars, 29,616 forks, MIT license, TypeScript
Read next
Security