Tools AI Risk Radar ai-incident-0083
Incident record
DeepSeek Harness accepted a spoofed loopback Host header as proof a request was local
- Severity
- Critical
- Status
- Patched
- Type
- Agent Hijack
- Target
- DeepSeek Harness before dsh-v0.1.2-alpha.1
- Actor
- researcher
- CVE
- CVE-2026-82533
What happened
The agent-control API authenticated requests by their Host header, so a client-supplied loopback value passed for a local caller. An attacker who reaches the port, including remotely where it is exposed, gains sandbox escape, can disable approval prompts and can read transcripts off the machine. NVD scores it CVSS 3.1 9.6. The dsh-v0.1.2-alpha.1 release requires every /api request to present a Host that is loopback or on a trusted list, adds one-time token authentication for network access and rejects --host 0.0.0.0.
Sources
- DeepSeek Harness release dsh-v0.1.2-alpha.1github.com/deepseek-ai/deepseek-harness/releases/tag/dsh-v0.…
- Fix commit, deepseek-ai/deepseek-harnessgithub.com/deepseek-ai/deepseek-harness/commit/3e24087bfaeab…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026