CVE Tools

CVE-2026-82533

DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

Published: Sep 8, 2026Updated: Sep 10, 2026 Sources: CVE List NVDCWE-807

Description

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to escape its own OS sandbox, escalate to unconfined execution, and disable the approval prompt. When the port is externally reachable via tunnel, SSH forward, or reverse proxy, a remote attacker can exploit the same flaw to create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials.

In plain language

AI Act now

DeepSeek Harness has a critical login bypass where attackers can get into restricted features without credentials by spoofing a network “Host” value; this is a serious problem if your Harness service is reachable over the network in its default setup.

Executive summary

In DeepSeek Harness (before 0.1.2-alpha.1), an authentication bypass (CWE-807) can be triggered by Host header spoofing, letting an unauthenticated attacker reach and use restricted functions by the application trusting the client-supplied Host rather than the real connection source; the issue is reachable in default configuration.

If affected, business impact
Unauthorized access to restricted featuresStored data exposure (transcripts)System takeover riskService disruption

What to do now

  1. Check whether your installed DeepSeek Harness version is older than 0.1.2-alpha.1.
  2. Check whether the Harness web service is reachable from outside your network (directly, via a tunnel/SSH forward, reverse proxy, or similar).
  3. If you’re using a vulnerable version, upgrade DeepSeek Harness to 0.1.2-alpha.1.
  4. After upgrading, restart the service and re-verify the running version matches 0.1.2-alpha.1.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

DeepSeek
commercial·CNaka deepseek-r1, deepseek-v2

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

References

and 1 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-82533 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows