DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
DeepSeek has released a fix for CVE-2026-82533, a critical flaw in the DeepSeek Harness tool that permitted AI coding agents to bypass their file-based sandbox restrictions. The vulnerability stemmed from a lack of proper authentication on the local web interface, allowing a malicious agent to issue a specific command that switched the session to a 'danger-full-access' mode, thereby disabling approval prompts and sandbox boundaries. Rated 9.4 by VulnCheck, this issue affected versions up to 0.1.1-rc.2 and enabled attackers to write files outside the designated workspace after exploiting the unsanitized Host header check. Users are advised to upgrade immediately to version 0.1.2-alpha.2 or later, as the initial fixed release was not available via npm.