Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

DeepSeek Harness lets a sandboxed agent escalate itself to full access via an unauthenticated API

DeepSeek Harness, DeepSeek's open-source agent runner, carries a 9.4-severity flaw that lets a sandboxed agent grant itself full access with one command. Its control API has no authentication and trusts a client-supplied Host header.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying DeepSeek Harness lets a sandboxed agent escalate itself to full access via an unauthenticated API
Generated illustration

What happened

  • The tool's OS sandbox blocks file writes but leaves loopback connections open and runs ordinary shell commands without an approval prompt.
  • DeepSeek's architecture docs state that every part of the tool, including the agent loop and the session log, is a plugin that can be swapped from configuration.
  • The harness is built on Cordis, a separate open-source composability framework that has existed since 2022 and now carries 9,108 GitHub stars.
  • DeepSeek Harness showed 246,721 GitHub stars when the article was written, up from the roughly 215,000 the Cloud Security Alliance counted weeks after launch.

Why it matters

  • constraint There is no central place to add authentication, because hardening the tool would mean replacing the very plugins the agent can already rewrite.
  • exposure A control port reachable beyond localhost becomes unauthenticated remote takeover of the agent and a full read of its saved conversations.
  • decision Any team adopting the fast-growing preview has to treat the control port as a trust boundary the tool does not enforce, and isolate it before use.

The control API's authorization check reads the Host header. The client sets that header, so the check trusts whatever the caller says it is. [10]

The sandbox does not contain this. From inside it the agent reaches the local control port and is trusted. In one request it raises its session to danger-full-access and switches approvals to no-ask. [12] From there every command runs outside the sandbox with no prompt.

The documentation says there is no special core to modify; you extend the tool by dropping a new plugin beside the existing ones. [6] The policy that decides whether a command needs sign-off sits in that same swappable configuration, within reach of the agent it is meant to govern.

Cordis, the framework underneath, is older and separate from the harness. [7] An arXiv paper sets out its model in two dimensions: undoing a component's side effects when it is removed, and declaring relationships between components so the runtime manages them automatically. [8] The paper is about composition, not security, and the control API's missing authentication is the harness's own choice.

The disclosure moved quickly. DeepSeek's own GitHub discussion posted the self-elevation technique on 13 and 14 August. [14] OX Security reported it to the CVE authority VulnCheck on 24 August, [15] and CVE-2026-82533 was published on 8 September. [9] The write-up assembling all of this was produced by a DeepSeek model running through Hermes Agent, with a person checking the output. [16]

What to watch

  • Whether DeepSeek ships a build that authenticates the control API or binds it to loopback by default.
  • Whether the shipped default exposes the control port to the network, the condition the disclosure sets for remote takeover.
  • Independent confirmation of the CVE-2026-82533 details, given the sole account here was itself written by an AI agent.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption55
Hype gap+20
Incentives
Insufficient
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    DeepSeek released an agent-running code tool called DeepSeek Harness in August 2026.

    ReportedSupportedView cited source
  2. [2]

    DeepSeek Harness is open source under the MIT license, written in TypeScript, and its GitHub project was started on 13 August 2026.

    ReportedSupportedView cited source
  3. [3]

    At the time the article was written, DeepSeek Harness showed 246,721 stars and 29,616 forks on GitHub.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 10, 2026

    DeepSeek Harness สองเดือนให้หลัง: ช่องโหว่ AI 9.4 บอกอะไรเรื่องกำแพงที่ไม่มี?

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories