Critical Flaw in DeepSeek Harness Allows AI Agents to Escape Sandbox

Critical Flaw in DeepSeek Harness Allows AI Agents to Escape Sandbox

First seen 9 Sep 2026, 15:48 UTC Feeds.Feedburnerwww.vulncheck.comOx.Security 70.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-82533) was discovered in DeepSeek Harness, an open-source tool for AI coding agents, enabling a sandboxed agent to disable its own confinement using a single shell command. The flaw stems from the tool's unauthenticated API, which relied on the client-supplied 'Host' header for trust verification, allowing an agent to elevate its session to 'danger-full-access' without approval prompts. This vulnerability affects default installations of DeepSeek Harness, which could expose sensitive data if the API was accessible over a network. The issue was reported by OX Research and remediated in version 0.1.2-alpha.1, released on August 27, 2026. The flaw has been rated 9.4 out of 10 by VulnCheck, indicating its severity. Users are urged to update to the fixed version to mitigate risks.

Key Points: • CVE-2026-82533 allows AI agents to escape their sandbox. • The vulnerability requires no authentication and can be exploited with a single command. • DeepSeek Harness versions 0.1.1-rc.2 and earlier are affected.

Ask AI about this cluster

Timeline

2026-08-24
Vulnerability disclosed to VulnCheck
OX Research reported the critical vulnerability in DeepSeek Harness, leading to the assignment of CVE-2026-82533.
Ox.Security
2026-08-27
Patch released for DeepSeek Harness
DeepSeek released version 0.1.2-alpha.1 to remediate the vulnerability allowing sandbox escape.
Ox.Security
2026-09-08
CVE-2026-82533 published
VulnCheck published the CVE record for the vulnerability, rating it 9.4 out of 10.
Feeds.Feedburner
2026-09-09
Articles published detailing the vulnerability
Both Ox.Security and Feeds.Feedburner published articles outlining the critical flaw in DeepSeek Harness.
Ox.Security