<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:deepseek:harness:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adeepseekharness/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 17:42:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adeepseekharness/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in DeepSeek Harness via Host Header Spoofing</title><link>https://feed.craftedsignal.io/briefs/2026-09-deepseek-harness-auth-bypass/</link><pubDate>Tue, 08 Sep 2026 17:42:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-deepseek-harness-auth-bypass/</guid><description>DeepSeek Harness versions prior to 0.1.2-alpha.1 contain an authentication bypass vulnerability allowing unauthorized remote control of the agent via a spoofed HTTP Host header.</description><content:encoded><![CDATA[<p>DeepSeek Harness versions prior to 0.1.2-alpha.1 are affected by a critical authentication bypass vulnerability located in the local HTTP control-plane API. The vulnerability exists because the API server relies on the client-provided HTTP Host header for security validation instead of verifying the actual TCP connection origin. This flaw permits an attacker to spoof the Host header, effectively bypassing all authentication mechanisms. Upon successful exploitation, an attacker can obtain full control over the agent, execute privileged commands, modify session approval policies to achieve unconfined execution, and exfiltrate all stored conversation history without the need for credentials or API keys. Defenders must prioritize upgrading to version 0.1.2-alpha.1 or later to remediate this control-plane exposure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-82533 results in total loss of confidentiality and integrity of the DeepSeek Harness agent. Unauthorized actors can exfiltrate sensitive conversation data and execute arbitrary commands with full agent privileges, leading to potential lateral movement if the agent has further access to internal infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following actions to secure environments using DeepSeek Harness:</p>
<ul>
<li>Upgrade all instances of DeepSeek Harness to version 0.1.2-alpha.1 or later immediately.</li>
<li>Restrict access to the HTTP control-plane API via network segmentation or firewall rules, ensuring only authorized administrative IP addresses can reach the interface.</li>
<li>Implement monitoring on the API to detect abnormal Host header values or unauthorized attempts to access the /commands/execute or session policy configuration endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>