Source · DiggingBeagle record
CVE-2026-82533: DeepSeek Harness AI Agent Sandbox Escape
OX Research technical disclosure describing the local control-plane trust flaw, reproduced sandbox escape, remote-exposure path, disclosure timeline and retest after the fix.
- Published
- Sep 8, 2026
- Accessed
- Sep 19, 2026
- Publisher
- OX Security
- Source type
- research_disclosure
- Version
- CVE-2026-82533
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
No network exposure, credentials, or changes from the shipped defaults were required.
Claim-level citations (6)
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: The vulnerability was fixed in DeepSeek Harness 0.1.2-alpha.1, and OX reports that it re-tested that release on August 30, 2026 and confirmed remediation.
Disclosure timeline: August 27 fix and August 30 re-test
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: When the local control port was made reachable through a tunnel, SSH forward or reverse proxy, the same flaw could allow an unauthenticated remote caller to create sessions, execute arbitrary commands and retrieve stored conversations.
Overview and remote-exposure discussion
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: OX reported a matched control in which the same out-of-workspace write was blocked in a confined session but succeeded after the otherwise identical session first removed its confinement.
Technical Details, matched-control comparison after 'The Sandbox Rewrites Itself'
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: OX Research reports reproducing the local sandbox escape on the shipped default configuration without externally exposing the control port or supplying credentials.
Overview: default installation, loopback networking, ordinary shell call and no network exposure or credentials required
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: OX reported that the policy change was recorded as user-sourced and that no approval/request event appeared, so the harness could not distinguish the agent's shell-originated request from human operator action.
Technical Details, session-log discussion after the sandbox escape
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: DeepSeek Harness before 0.1.2-alpha.1 allowed a process confined by the harness sandbox to call the local agent-control API with a spoofed loopback Host value and switch the session to danger-full-access with approval disabled.
Overview and Technical Details sections describing isTrustedApiRequest and the single-command sandbox escape
Cite this record
DiggingBeagle. “CVE-2026-82533: DeepSeek Harness AI Agent Sandbox Escape.” Published Sep 8, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape/
Citation guidance