Tools
An unauthenticated RCE proof of concept for exposed DeepSeek Harness web instances is public on GitHub
ChaoMixian/dsh2shell, created 2026-08-21 and at 37 stars with 11 forks, is a Python proof of concept for unauthenticated remote code execution against DeepSeek Harness web instances reachable on the network. It arrives while the DSH plugin ecosystem is scaling fast: dshplugin/dsh-plugin-hub advertises 4,000+ community plugins installable from inside the app's settings panel, updated daily. Anyone who exposed a dsh web instance beyond localhost should treat this as an active exposure, and the plugin hub's install-from-app flow is worth auditing on the same pass.
Source
↳ Follow the thread