Description
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to escape its own OS sandbox, escalate to unconfined execution, and disable the approval prompt. When the port is externally reachable via tunnel, SSH forward, or reverse proxy, a remote attacker can exploit the same flaw to create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials.
Published: 2026-09-08
Score: 9.4 Critical
EPSS: 1.2% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

DeepSeek Harness before version 0.1.2‑alpha.1 grants unauthenticated access to its local HTTP agent‑control API by accepting a client‑supplied loopback Host header instead of validating the actual TCP connection origin. This flaw corresponds to the weakness type CWE‑807. This flaw allows an attacker to execute privileged commands, escape the OS sandbox, elevate to unconfined execution, and disable the approval prompt. When the API is reachable externally via tunnel or proxy, the attacker can create sessions, run arbitrary commands, and exfiltrate stored conversation transcripts without credentials, effectively granting full control over the harness and enabling remote code execution.

Affected Systems

The vulnerability is present in all releases of DeepSeek Harness older than 0.1.2‑alpha.1, excluding the 0.1.2‑alpha.1 release. Systems running these affected versions, regardless of deployment scale, are susceptible.

Risk and Exploitability

The CVSS score of 9.4 classifies this issue as critical, indicating that exploitation can compromise confidentiality, integrity, and availability. The EPSS score is < 1%, indicating a low but nonzero probability of exploitation. The vulnerability is present in the local control‑plane HTTP API of DeepSeek Harness versions older than 0.1.2‑alpha.1. To exploit the flaw, an attacker must be able to send requests to this API and supply a spoofed Host header; the server validates the header value rather than the actual TCP origin. When the bypass succeeds, the attacker can invoke privileged commands such as /commands/execute with full‑access rights, elevate session approval policies, and retrieve all stored conversations.

Generated by OpenCVE AI on September 10, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DeepSeek Harness to version 0.1.2‑alpha.1 or newer to receive the fix that validates the Host header against the TCP connection origin.
  • Restrict network access to the harness control‑plane API to trusted hosts or require standard authentication mechanisms before any API calls, ensuring that only authorized clients can communicate.
  • If an immediate upgrade is not feasible, manually enforce Host header validation at the application level or block suspicious Host header values by configuring the web server or reverse proxy to reject requests that contain a Host header not matching the expected value.
  • Monitor API traffic for anomalous Host header usage and audit any privileged command executions for possible exploitation.

Generated by OpenCVE AI on September 10, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:00:00 +0000


Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key. DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to escape its own OS sandbox, escalate to unconfined execution, and disable the approval prompt. When the port is externally reachable via tunnel, SSH forward, or reverse proxy, a remote attacker can exploit the same flaw to create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials.

Tue, 08 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key.
Title DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:09.857Z

Reserved: 2026-08-29T17:20:57.082Z

Link: CVE-2026-82533

cve-icon Vulnrichment

Updated: 2026-09-08T17:21:08.238Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T17:18:36.887

Modified: 2026-09-10T15:17:47.593

Link: CVE-2026-82533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:45:17Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision