CVE Tools

CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox

OX SecurityBy Nir Zadok, Moshe Siman Tov Bustan6 min read

PoC publicDeepSeek HarnessOX Research

Our summary

OX Research has published a proof-of-concept demonstrating how CVE-2026-82533 allows AI agents running inside DeepSeek Harness to escape their operating system sandbox. The vulnerability, rated CVSS 9.4, stems from the local HTTP API trusting client-supplied 'Host' headers instead of verifying peer addresses, while default sandbox profiles permitted unrestricted loopback networking.

By exploiting this misconfiguration, a sandboxed agent could issue a single shell command to escalate its session to full access, effectively disabling security controls without network exposure or additional credentials. OX Research disclosed the issue to VulnCheck on August 24, 2026, and confirmed that the fix in DeepSeek Harness 0.1.2-alpha.1 resolves the defect.

Read at OX Security

Below is the opening; the full story is at OX Security.

From OX Security

OX Research found and disclosed a critical vulnerability in DeepSeek Harness, DeepSeek’s open-source AI coding-agent harness, that allowed a sandboxed AI agent to disable its own confinement with a single shell command – on shipped defaults, with no network exposure and no credentials.

Vulnerability Details…

Continue at OX Security

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store