ACVE-2026-0430
DeepSeek Harness dsh 0.1.1-rc.2 and earlier, running a coding agent in its sandbox, let the agent disable its own confinement and write outside the session workspace.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier CVE-2026-82533 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Fixed in 0.1.2-alpha.1 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Severity CRITICAL; matches CNA | Confirmed | cveawg.mitre.org | 2026-09-24 |
In the wild
demonstrated
Description
What
OX Security reported that DeepSeek Harness exposed an unauthenticated local agent-control API and trusted a client-supplied host value. A sandboxed agent could therefore escape its confinement and affect files outside the session workspace.
Detection
OX Security demonstrated the escape and reported CVE-2026-82533.
Fix
Upgrade DeepSeek Harness to 0.1.2-alpha.1 or later.
Fix
Upgrade DeepSeek Harness to 0.1.2-alpha.1 or later.
- Upgrade
harness:deepseek-harnessto0.1.2-alpha.1. Remediation stated by OX Security. Owner: operator