{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adeepseekharness/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:deepseek:harness:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-82533"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Harness (\u003c 0.1.2-alpha.1)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["DeepSeek"],"content_html":"\u003cp\u003eDeepSeek Harness versions prior to 0.1.2-alpha.1 are affected by a critical authentication bypass vulnerability located in the local HTTP control-plane API. The vulnerability exists because the API server relies on the client-provided HTTP Host header for security validation instead of verifying the actual TCP connection origin. This flaw permits an attacker to spoof the Host header, effectively bypassing all authentication mechanisms. Upon successful exploitation, an attacker can obtain full control over the agent, execute privileged commands, modify session approval policies to achieve unconfined execution, and exfiltrate all stored conversation history without the need for credentials or API keys. Defenders must prioritize upgrading to version 0.1.2-alpha.1 or later to remediate this control-plane exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-82533 results in total loss of confidentiality and integrity of the DeepSeek Harness agent. Unauthorized actors can exfiltrate sensitive conversation data and execute arbitrary commands with full agent privileges, leading to potential lateral movement if the agent has further access to internal infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure environments using DeepSeek Harness:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of DeepSeek Harness to version 0.1.2-alpha.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eRestrict access to the HTTP control-plane API via network segmentation or firewall rules, ensuring only authorized administrative IP addresses can reach the interface.\u003c/li\u003e\n\u003cli\u003eImplement monitoring on the API to detect abnormal Host header values or unauthorized attempts to access the /commands/execute or session policy configuration endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T17:42:13Z","date_published":"2026-09-08T17:42:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-deepseek-harness-auth-bypass/","summary":"DeepSeek Harness versions prior to 0.1.2-alpha.1 contain an authentication bypass vulnerability allowing unauthorized remote control of the agent via a spoofed HTTP Host header.","title":"Authentication Bypass in DeepSeek Harness via Host Header Spoofing","url":"https://feed.craftedsignal.io/briefs/2026-09-deepseek-harness-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:deepseek:harness:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}