Product
DeepSeek Harness versions prior to 0.1.2-alpha.1 contain an authentication bypass vulnerability allowing unauthorized remote control of the agent via a spoofed HTTP Host header.