OX Research reported CVE-2026-82533 in DeepSeek Harness, a tool for running AI agents. According to the researchers, an agent in the sandbox could disable its own confinement with one command.

The report links the issue to an unauthenticated local control API that trusted the Host header supplied by the client. It says versions 0.1.1-rc.2 and earlier are affected, and recommends updating to 0.1.2-alpha.1 or later to resolve the issue.

Claim check:

  • OX Research reported CVE-2026-82533 in DeepSeek Harness. (confirmed by the publication itself: evidence; «OX Research found and disclosed a critical vulnerability in DeepSeek Harness, DeepSeek’s open-source AI coding-agent harness, that allowed a sandboxed AI agent to disable its own confinement with a single shell command – on shipped defaults, with no network exposure and no credentials.»)
  • According to OX Research, the vulnerability allowed an agent in the sandbox to disable its own confinement with one command. (confirmed by the publication itself: evidence; «That meant a single command was enough. From inside the sandbox, the agent could call the harness’s own unauthenticated API and elevate its session to ‘danger-full-access’ with approval set to ‘never’. Every command after that ran unconfined and without prompting.»)
  • The OX Research report says that DeepSeek Harness’s control API was available on a local HTTP port without authentication and determined trust from the Host header supplied by the client. (confirmed by the publication itself: evidence; «DeepSeek Harness exposed its agent-control API on a local HTTP port without authentication, relying solely on the client-supplied ‘Host’ request header to determine whether a request was trusted rather than verifying the connection’s actual peer address.»)
  • The OX Research report states that DeepSeek Harness 0.1.1-rc.2 and earlier are affected. (confirmed by the publication itself: evidence; «Affected Product(s) Version(s) DeepSeek Harness (dsh) 0.1.1-rc.2 and earlier»)
  • The OX Research report recommends updating DeepSeek Harness to 0.1.2-alpha.1 or later. (confirmed by the publication itself: evidence; «To resolve this issue, upgrading to DeepSeek Harness 0.1.2-alpha.1 or later is recommended.»)

Primary sources:

score 84.1 · kind incident · revision 1 · stories st-2n2nif