CVE-2026-82533
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
Description
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to escape its own OS sandbox, escalate to unconfined execution, and disable the approval prompt. When the port is externally reachable via tunnel, SSH forward, or reverse proxy, a remote attacker can exploit the same flaw to create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials.
In plain language
AI Act nowDeepSeek Harness has a critical login bypass where attackers can get into restricted features without credentials by spoofing a network “Host” value; this is a serious problem if your Harness service is reachable over the network in its default setup.
In DeepSeek Harness (before 0.1.2-alpha.1), an authentication bypass (CWE-807) can be triggered by Host header spoofing, letting an unauthenticated attacker reach and use restricted functions by the application trusting the client-supplied Host rather than the real connection source; the issue is reachable in default configuration.
What to do now
- Check whether your installed DeepSeek Harness version is older than 0.1.2-alpha.1.
- Check whether the Harness web service is reachable from outside your network (directly, via a tunnel/SSH forward, reverse proxy, or similar).
- If you’re using a vulnerable version, upgrade DeepSeek Harness to 0.1.2-alpha.1.
- After upgrading, restart the service and re-verify the running version matches 0.1.2-alpha.1.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkitsen·The Hacker News· Exploited RubyGems Chaotic Eclipse
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approvalen·The Hacker News· Patch DeepSeek Harness auth-bypass
- CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandboxen-us·OX Security· PoC DeepSeek Harness OX Research
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-82533 and every CVE in our database. Create a free account — no credit card required.
Create Free Account