PT-2026-87187 · Deepseek+1 · Deepseek Harness
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DeepSeek Harness versions prior to 0.1.2-alpha.1
Description
An authentication bypass exists in the local HTTP agent-control API. The system grants unauthenticated access by accepting a client-supplied loopback
Host header instead of validating the actual TCP connection origin. In default configurations, a confined process executed by a tool can reach the loopback API without port exposure to escape its OS sandbox, escalate to unconfined execution, and disable approval prompts. If the port is externally reachable via reverse proxy, SSH forward, or tunnel, a remote attacker can create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials.Recommendations
Update DeepSeek Harness to version 0.1.2-alpha.1 or newer.
As a temporary mitigation, disable the web interface and close any open tunnels or port forwards.
Restrict access to the local HTTP agent-control API to prevent unauthorized loopback requests.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deepseek Harness