Input Validation Flaw in Deepseek-AI's Deepseek-Harness by Deepseek
CVE-2026-101131

4.8MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101131?

A vulnerability exists in the Deepseek-Harness component, specifically in the handling of the E2B_API_KEY due to reliance on untrusted inputs, which can compromise security decision-making. This issue is present in versions up to 0.1.5-rc.3 and allows attackers with local access to potentially exploit the flaw. The vulnerability was disclosed to the vendor without any response, increasing the urgency for users to assess their security posture.

Affected Version(s)

deepseek-harness 0.1.5-rc.0

deepseek-harness 0.1.5-rc.1

deepseek-harness 0.1.5-rc.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Piggy Sprint (VulDB User)
VulDB CNA Team
.