CVE-2026-82533 PUBLISHED

DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

Assigner: VulnCheck
Reserved: 29.08.2026 Published: 08.09.2026 Updated: 08.09.2026

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor DeepSeek
Product DeepSeek Harness
Versions Default: unaffected
  • affected from 0 to 0.1.2-alpha.1 (excl.)

Credits

  • Nir Zadok (Nirza) finder
  • Moshe Siman Tov Bustan finder

References

Problem Types

  • Reliance on Untrusted Inputs in a Security Decision CWE