CVE Tools

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

The Hacker NewsBy The Hacker News

PatchDeepSeek Harness

Our summary

DeepSeek has released a fix for CVE-2026-82533, a critical flaw in the DeepSeek Harness tool that permitted AI coding agents to bypass their file-based sandbox restrictions. The vulnerability stemmed from a lack of proper authentication on the local web interface, allowing a malicious agent to issue a specific command that switched the session to a 'danger-full-access' mode, thereby disabling approval prompts and sandbox boundaries. Rated 9.4 by VulnCheck, this issue affected versions up to 0.1.1-rc.2 and enabled attackers to write files outside the designated workspace after exploiting the unsanitized Host header check. Users are advised to upgrade immediately to version 0.1.2-alpha.2 or later, as the initial fixed release was not available via npm.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store