Impact
DeepSeek Harness before version 0.1.2‑alpha.1 grants unauthenticated access to its local HTTP agent‑control API by accepting a client‑supplied loopback Host header instead of validating the actual TCP connection origin. This flaw corresponds to the weakness type CWE‑807. This flaw allows an attacker to execute privileged commands, escape the OS sandbox, elevate to unconfined execution, and disable the approval prompt. When the API is reachable externally via tunnel or proxy, the attacker can create sessions, run arbitrary commands, and exfiltrate stored conversation transcripts without credentials, effectively granting full control over the harness and enabling remote code execution.
Affected Systems
The vulnerability is present in all releases of DeepSeek Harness older than 0.1.2‑alpha.1, excluding the 0.1.2‑alpha.1 release. Systems running these affected versions, regardless of deployment scale, are susceptible.
Risk and Exploitability
The CVSS score of 9.4 classifies this issue as critical, indicating that exploitation can compromise confidentiality, integrity, and availability. The EPSS score is < 1%, indicating a low but nonzero probability of exploitation. The vulnerability is present in the local control‑plane HTTP API of DeepSeek Harness versions older than 0.1.2‑alpha.1. To exploit the flaw, an attacker must be able to send requests to this API and supply a spoofed Host header; the server validates the header value rather than the actual TCP origin. When the bypass succeeds, the attacker can invoke privileged commands such as /commands/execute with full‑access rights, elevate session approval policies, and retrieve all stored conversations.
OpenCVE Enrichment