Executive brief
DeepSeek Harness is a desktop application framework that runs AI agents with sandboxed execution. A flaw in its HTTP agent-control API allows attackers to bypass authentication by spoofing the loopback host header. Confined processes can escape their sandbox and disable approval prompts; if the API is exposed via tunneling or proxy, remote attackers can execute arbitrary commands and steal conversation transcripts without any credentials.
Technical details
The vulnerability is an authentication bypass in DeepSeek Harness's local HTTP agent-control API, which validates the client-supplied Host header instead of verifying the actual TCP connection source (localhost/loopback). This allows a confined tool-executed process to reach the API and execute privileged operations, including OS sandbox escape, privilege escalation, and approval-prompt disabling. When the API port is externally exposed (via SSH tunnel, reverse proxy, or similar), a remote unauthenticated attacker can exploit the same flaw to create sessions, execute commands, and exfiltrate conversation transcripts. The fix, committed 2026-08-25, adds proper Host API authentication; patch released in version 0.1.2-alpha.1 (2026-08-27).
Affected products
- DeepSeek Harness before 0.1.2-alpha.1
Timeline
- 2026-09-08: disclosed: CVE-2026-82533 published on NVD
- 2026-08-27: patched: Fix released in version 0.1.2-alpha.1
- 2026-08-25: other: Authentication bypass patch committed to repository