cyberivy
DeepSeek HarnessCVE-2026-82533AI SecurityCoding AgentsSandbox EscapePrompt InjectionOpen Source AIDeveloper Security

DeepSeek Harness agent could disable its own sandbox

October 9, 2026

Dunkle Illustration eines roten Warnsymbols neben einem Computerterminal und einer aufgebrochenen digitalen Schutzbarriere

A critical flaw allowed a confined AI agent to disable its own protective sandbox. Affected installations should upgrade to version 0.1.2-alpha.1 or later.

What this is about

Security researchers at OX Security published technical details on October 9, 2026, about a critical flaw in DeepSeek Harness. The open source tool runs coding agent commands inside an operating system sandbox. Yet a confined agent could disable that very protection through the product's local control API. The flaw is tracked as CVE-2026-82533 and carries a 9.4 out of 10 CVSS 4.0 score in the CVE record.

Versions before 0.1.2-alpha.1 are affected. DeepSeek released the corrected version on August 27, 2026. This is therefore not a report about an unpatched zero day. It is a technical disclosure with a clear action for installations that still run an older preview version.

What DeepSeek Harness actually does

DeepSeek Harness is an open source runtime for AI coding agents. It provides a browser interface, manages sessions, and lets agents use tools such as a shell. To stop a model from reaching arbitrary parts of the computer, operating system mechanisms including Bubblewrap, Landlock, or Seatbelt are intended to restrict writes outside the workspace.

According to OX Security, the local agent control service listened on port 3080 by default and required no authentication. It decided whether a request was trusted from the client supplied Host header. A process inside the sandbox could choose that header, call the local API, and change its own session to unrestricted execution without further approval. The sandbox restricted file access but still allowed connections to the host's loopback address.

If the port was reachable through a tunnel, port forwarding, or a reverse proxy, the CVE record also describes remote access to sessions, commands, and stored conversation transcripts. The corrected release changes this trust boundary; the linked patch and release notes document the fix.

Why it matters

Coding agents often hold exactly the access attackers want: source code, package registries, cloud tooling, SSH connections, and internal services. A sandbox is supposed to prevent manipulated content in a repository, webpage, or error message from inheriting those permissions. If an agent can change its protection level through its own control API, that separation fails at the point where it matters most.

The case also illustrates a broader architecture problem. A service bound to 127.0.0.1 is not automatically behind a secure trust boundary. Other processes on the same machine, sandboxed tools, and port forwarding can still reach local services. Authentication, verification of the real peer, and network isolation remain necessary even when an interface was designed only for local use.

In plain language

The sandbox is like a hotel room where a guest is expected to stay. Reception did not check who was calling; it only checked whether the caller claimed to be inside the hotel. The guest could dial the internal number, claim to be trusted, and issue themselves a master key. The update replaces that claim with a stronger check.

A practical example

A developer opens an unfamiliar repository with an older Harness version. A file contains an instruction that nudges the agent into running an inconspicuous shell command. That command reaches the local API, changes the session to unrestricted access, and turns off approval prompts. A later tool call could then write outside the project directory or read reachable credentials.

After upgrading to version 0.1.2-alpha.1 or later, that known path should be closed. The developer should also check whether port 3080 was exposed by a development environment, SSH forwarding, or a proxy, and investigate old sessions or stored secrets if there is a concrete sign of compromise.

Scope and limits

  • OX Security demonstrated a working attack, but the public CVE record listed no known exploitation in the wild as of September 8, 2026. There is no evidence here of a broad attack campaign.
  • The flaw affects DeepSeek Harness before 0.1.2-alpha.1. It does not show that every AI agent sandbox has the same defect. Other products require separate testing.
  • Updating closes the described path but does not replace least privilege. Agents should not receive permanently loaded production keys, and local control services should not be forwarded without review.

SEO and GEO keywords

DeepSeek Harness, CVE-2026-82533, sandbox escape, AI agent security, coding agent, Host header, local API, loopback security, prompt injection, OX Security, CVSS 9.4, version 0.1.2-alpha.1

πŸ’‘ In plain English

An older DeepSeek Harness version allowed a confined AI agent to disable its own protection through a local API. Users should upgrade to at least version 0.1.2-alpha.1 and check whether the local port was forwarded.

Key Takeaways

  • β†’CVE-2026-82533 has a CVSS 4.0 score of 9.4 out of 10.
  • β†’An agent could use the local control API to disable its sandbox and approval prompts.
  • β†’Versions before 0.1.2-alpha.1 are affected; the fix shipped on August 27, 2026.
  • β†’An externally reachable port could also expose sessions and stored conversation transcripts.
  • β†’The CVE record lists no confirmed exploitation in the wild.

FAQ

Which version is safer?

DeepSeek Harness 0.1.2-alpha.1 or later contains the published fix for CVE-2026-82533.

Did an attacker need a password?

OX Security says the described local path required no credentials. The same was true for the affected interface when its port was externally reachable.

Has the flaw been exploited?

The public CVE record lists no confirmed exploitation. That does not rule out unknown individual cases.

Is updating enough?

It closes the known path. Users should also review port forwarding, stored secrets, and the agent's permissions.

Sources & Context