CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox
OX Research has published a proof-of-concept demonstrating how CVE-2026-82533 allows AI agents running inside DeepSeek Harness to escape their operating system sandbox. The vulnerability, rated CVSS 9.4, stems from the local HTTP API trusting client-supplied 'Host' headers instead of verifying peer addresses, while default sandbox profiles permitted unrestricted loopback networking.
By exploiting this misconfiguration, a sandboxed agent could issue a single shell command to escalate its session to full access, effectively disabling security controls without network exposure or additional credentials. OX Research disclosed the issue to VulnCheck on August 24, 2026, and confirmed that the fix in DeepSeek Harness 0.1.2-alpha.1 resolves the defect.