Critical Vulnerability in DeepSeek Harness Allows AI Agents to Bypass File Sandbox Restrictions
A critical vulnerability (CVE-2026-82533) in DeepSeek Harness allows AI agents to disable their own file sandbox without approval by exploiting the tool's local web interface. The flaw was patched in version 0.1.2-alpha.2, but users are advised to upgrade to mitigate risks, as the sandboxing mechanisms do not guarantee isolation.
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command.
The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
*** END OF TRANSMISSION ***