NPM · SEPTEMBER 2026 · EARLY WARNING

DeepSeek Harness Vulnerability: Critical Authentication Bypass Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.6
Affected component
deepseek harness (npm)
Affected versions
>= dsh-v0.1.1-rc.2, <= dsh-v0.1.1-rc.2 or >= dsh-v0.1.1-rc.1, <= dsh-v0.1.1-rc.1 or >= dsh-v0.1.0-rc.8, <= dsh-v0.1.0-rc.8 or >= dsh-v0.1.0-rc.7, <= dsh-v0.1.0-rc.7
Patched version
0.1.2-alpha.1
CVE-2026-82533

An authentication bypass vulnerability has been reported in DeepSeek Harness versions prior to 0.1.2-alpha.1. This flaw could allow attackers to gain full control over the agent by spoofing a Host header.

What happened

DeepSeek Harness, an open-source tool for running AI coding agents, reportedly contains a critical vulnerability. This flaw, tracked as CVE-2026-82533, allows an attacker to bypass authentication in the local HTTP control-plane API. By supplying a spoofed Host header, an attacker could gain full control over the agent. The vulnerability affects versions of DeepSeek Harness from dsh-v0.1.0-rc.7 to dsh-v0.1.1-rc.2. The issue has been patched in version 0.1.2-alpha.1.

The vulnerability was discovered by OX Research and reported to DeepSeek. It was assigned a CVSS score of 9.6, indicating a critical severity level. The flaw allowed a sandboxed agent to disable its own sandbox without approval, potentially leading to unauthorized access to the host system.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If deepseek harness is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using DeepSeek Harness versions from dsh-v0.1.0-rc.7 to dsh-v0.1.1-rc.2.

What should I do right now?

Upgrade to DeepSeek Harness version 0.1.2-alpha.1 or later and review your system for any unauthorized access.

Is there an official fix available?

Yes, the vulnerability has been patched in DeepSeek Harness version 0.1.2-alpha.1.

Sources

Join the 0Day waitlist →

← Back to all threats