DeepSeek Harness flaw let AI agents disable their own sandbox
A critical DeepSeek Harness vulnerability let a coding agent switch itself into unrestricted mode with one shell command, bypassing both file-sandbox protections and approval prompts. CVE-2026-82533 affects versions through 0.1.1-rc.2, and administrators should install 0.1.2-alpha.2 or later because the first fixed version listed by the project was not published to npm.
Source
👉@sysadminoff
https://4sysops.com/archives/deepseek-harness-flaw-let-ai-agents-disable-their-own-sandbox/
Post #19980
70
