DeepSeek Harness sandbox escape (CVE-2026-82533)
Vulnerability
Summary
Hide ▲
Show ▼
DeepSeek Harness had a sandbox escape flaw that let a sandboxed agent call the local interface and switch the session to danger-full-access on default installations. CVE-2026-82533 affected 0.1.1-rc.2 and earlier until DeepSeek's August 27 fix. The bug could enable outside-workspace writes and session log retrieval without approval. VulnCheck later published the record on September 8 and rated it 9.4/10.
Related Happenings
Isolated-vm ExternalCopy type confusion GHSA-864f-rcv7-6rh4 remote code execution flaw
Vulnerability
H score16
First: 20.08.2026 16:48
Last: 20.08.2026 16:48
Sources 1
About this happening:
isolated-vm users face a critical ExternalCopy type confusion flaw that can let sandboxed JavaScript escape into the host process and corrupt memory across all versi...
Isolated-vm ExternalCopy type confusion GHSA-864f-rcv7-6rh4 remote code execution flaw
VulnerabilityAbout this happening: isolated-vm users face a critical ExternalCopy type confusion flaw that can let sandboxed JavaScript escape into the host process and corrupt memory across all versi...
Timeline
-
09.09.2026 14:17 1 articles · 1h ago
Sandboxed DeepSeek Harness agent escapes to danger-full-access
Initial DisclosureA developer on DeepSeek's discussion board showed that a process still held by the sandbox could reach DeepSeek Harness's local interface and switch the session to danger-full-access, demonstrating a sandbox escape on a default local installation.
Show sources
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval — thehackernews.com — 09.09.2026 14:17
-
09.09.2026 14:17 1 articles · 1h ago
DeepSeek Harness interface accepts requests without credentials
Technical Analysis UpdateAnother developer documented the same DeepSeek Harness interface accepting requests without any credentials, reinforcing that the local web interface lacked an authentication check.
Show sources
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval — thehackernews.com — 09.09.2026 14:17
-
09.09.2026 14:17 1 articles · 1h ago
OX Research reports the DeepSeek Harness sandbox escape to VulnCheck
Untyped PhaseOX Research reported the DeepSeek Harness sandbox escape to VulnCheck after validating that a default sandbox had been working before the escape and that one shell command could invoke the local interface and switch the session to danger-full-access.
Show sources
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval — thehackernews.com — 09.09.2026 14:17
-
09.09.2026 14:17 2 articles · 1h ago
DeepSeek fixes DeepSeek Harness sandbox escape
Mitigation Patch UpdateDeepSeek fixed DeepSeek Harness on August 27 after the affected release had allowed a sandboxed agent to call the local web interface and run commands outside the OS sandbox without an approval prompt on default installations.
Show sources
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval — thehackernews.com — 09.09.2026 14:17
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval — thehackernews.com — 09.09.2026 14:17
-
09.09.2026 14:17 1 articles · 1h ago
VulnCheck publishes CVE-2026-82533 and rates it 9.4/10
Attribution UpdateVulnCheck published CVE-2026-82533 for the DeepSeek Harness sandbox escape on September 8 and rated the flaw 9.4 out of 10, formalizing the identifier for the unauthenticated local-interface issue.
Show sources
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval — thehackernews.com — 09.09.2026 14:17