Source · DiggingBeagle record
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
VulnCheck CNA advisory for CVE-2026-82533, including affected versions, CWE-807, CVSS 4.0 9.4 and the local and remotely exposed control-plane attack paths.
- Published
- Sep 8, 2026
- Accessed
- Sep 19, 2026
- Publisher
- VulnCheck
- Source type
- cna_advisory
- Version
- CVE-2026-82533
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability.
Claim-level citations (3)
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: When the local control port was made reachable through a tunnel, SSH forward or reverse proxy, the same flaw could allow an unauthenticated remote caller to create sessions, execute arbitrary commands and retrieve stored conversations.
Description: externally reachable port scenario
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: VulnCheck lists CVE-2026-82533 as CWE-807 and scores it 9.4 under CVSS v4.
Advisory header: affected versions, CVE, CWE, CVSS and vector
- supportsDeepSeek Harness let a confined agent disable its own sandbox through the local control plane: DeepSeek Harness before 0.1.2-alpha.1 allowed a process confined by the harness sandbox to call the local agent-control API with a spoofed loopback Host value and switch the session to danger-full-access with approval disabled.
Description: local HTTP agent-control API Host-header authentication bypass and sandbox escalation
Cite this record
DiggingBeagle. “DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing.” Published Sep 8, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/deepseek-harness-0-1-2-alpha-1-authentication-bypass-via-host-header-spoofing/
Citation guidance