Authentication Bypass in DeepSeek Harness by DeepSeek
CVE-2026-82533
9.4CRITICAL
What is CVE-2026-82533?
DeepSeek Harness, prior to version 0.1.2-alpha.1, exhibits a security flaw in its local HTTP control-plane API. This flaw allows attackers to bypass authentication by manipulating the Host header, leading to unauthorized control of the agent. The server improperly validates the Host header value provided by the client rather than the actual origin of the TCP connection. With this vulnerability, an attacker can execute privileged commands, escalate session approval policies to permit unrestricted execution, and access all stored conversations without requiring any credentials or API keys.
Affected Version(s)
DeepSeek Harness 0 < 0.1.2-alpha.1
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nir Zadok (Nirza)
Moshe Siman Tov Bustan
