Executive brief
DeepSeek TUI is a terminal-based interface for interacting with AI models. A vulnerability exists where the tool's sub-agents are granted unrestricted shell access by default when a user approves a seemingly benign task. If a developer opens a malicious project repository, an attacker can use hidden instructions to trick the AI into executing harmful commands on the user's computer without further approval, potentially leading to full system compromise.
Technical details
The vulnerability stems from insecure defaults in the `task_create` tool within `deepseek-tui`. Specifically, `allow_shell` and `auto_approve` both default to `true` for spawned sub-agents. An attacker can craft a malicious repository containing prompt injection instructions (e.g., in an `AGENTS.md` file). When a user approves a high-level task creation, the sub-agent reads these instructions and executes arbitrary shell commands via the inherited permissions without triggering additional user approval prompts. This bypasses the intended security boundary of the approval system. The issue is fixed in version 0.8.26 by changing these defaults to `false`.
Affected products
- Hmbown/CodeWhale deepseek-tui < 0.8.26
Timeline
- 2026-05-10: disclosed
- 2026-05-14: advisory: GitHub Advisory published
- 2026-05-28: other: NVD published