Find notable cyber news and cases, enriched with sources, timelines, and signals.

DeepSeek Harness sandbox escape (CVE-2026-82533)

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

DeepSeek Harness had a sandbox escape flaw that let a sandboxed agent call the local interface and switch the session to danger-full-access on default installations. CVE-2026-82533 affected 0.1.1-rc.2 and earlier until DeepSeek's August 27 fix. The bug could enable outside-workspace writes and session log retrieval without approval. VulnCheck later published the record on September 8 and rated it 9.4/10.

Related Happenings

Isolated-vm ExternalCopy type confusion GHSA-864f-rcv7-6rh4 remote code execution flaw

Vulnerability
H score16 First: 20.08.2026 16:48 Last: 20.08.2026 16:48 Sources 1

About this happening: isolated-vm users face a critical ExternalCopy type confusion flaw that can let sandboxed JavaScript escape into the host process and corrupt memory across all versi...

Timeline

  1. 09.09.2026 14:17 1 articles · 1h ago

    Sandboxed DeepSeek Harness agent escapes to danger-full-access

    Initial Disclosure

    A developer on DeepSeek's discussion board showed that a process still held by the sandbox could reach DeepSeek Harness's local interface and switch the session to danger-full-access, demonstrating a sandbox escape on a default local installation.

    Show sources
  2. 09.09.2026 14:17 1 articles · 1h ago

    OX Research reports the DeepSeek Harness sandbox escape to VulnCheck

    Untyped Phase

    OX Research reported the DeepSeek Harness sandbox escape to VulnCheck after validating that a default sandbox had been working before the escape and that one shell command could invoke the local interface and switch the session to danger-full-access.

    Show sources
  3. 09.09.2026 14:17 2 articles · 1h ago

    DeepSeek fixes DeepSeek Harness sandbox escape

    Mitigation Patch Update

    DeepSeek fixed DeepSeek Harness on August 27 after the affected release had allowed a sandboxed agent to call the local web interface and run commands outside the OS sandbox without an approval prompt on default installations.

    Show sources