{"schema_version":"1.9.0","id":"GHSA-8m2g-8cgm-3vcp","published":"2026-09-08T18:32:01Z","modified":"2026-10-07T21:00:04.349245572Z","aliases":["CVE-2026-82533"],"summary":"DeepSeek Harness contains an authentication bypass vulnerability in local HTTP control-plane API","details":"DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key.","affected":[{"package":{"name":"@deepseek-ai/dsh-client-connection","ecosystem":"npm","purl":"pkg:npm/%40deepseek-ai/dsh-client-connection"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.2-alpha.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-8m2g-8cgm-3vcp/GHSA-8m2g-8cgm-3vcp.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82533"},{"type":"WEB","url":"https://github.com/deepseek-ai/deepseek-harness/commit/3e24087bfaeabe40b58ba2f7b936895b8f93fe27"},{"type":"PACKAGE","url":"https://github.com/deepseek-ai/deepseek-harness"},{"type":"WEB","url":"https://github.com/deepseek-ai/deepseek-harness/releases/tag/dsh-v0.1.2-alpha.1"},{"type":"WEB","url":"https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/deepseek-harness-alpha-1-authentication-bypass-via-host-header-spoofing"}],"database_specific":{"cwe_ids":["CWE-807"],"github_reviewed":true,"github_reviewed_at":"2026-10-07T20:41:36Z","nvd_published_at":"2026-09-08T17:18:36Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}