Official company update
CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox
OX Security·ox.security·
What the source says
OX Research found and disclosed a critical vulnerability in DeepSeek Harness, DeepSeek’s open-source AI coding-agent harness, that allowed a sandboxed AI agent to disable its own confinement with a single shell command – on shipped defaults, with no network exposure and no credentials. Vulnerability Details CVE: CVE-2026-82533 CWE: CWE-807 Relian
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about OX Security
Official · ox.security“Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With MalwareOfficial · ox.securitySSRF in Harbor Webhooks: Any User Can Reach the Server’s Cloud CredentialsOfficial · ox.securityCVE-2026-93355: Account Takeover in LiteLLMOfficial · ox.securityPhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels