Agents
DeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UI
OX Research found that DeepSeek Harness 0.1.1-rc.2 and earlier exposed a local web interface protected only by a Host-header check. A sandboxed agent, steered by attacker-supplied text, could run a single shell command against that interface to disable file restrictions and approval prompts. VulnCheck published the record on 2026-09-08 and The Hacker News covered it on 2026-09-09. Version 0.1.2-rc.1 adds a one-time startup token exchanged for signed cookies. Any agent harness that exposes a localhost control plane needs real authentication, because the agent itself can reach localhost.
↳ Follow the thread