Vulnerability GHSA-8m2g-8cgm-3vcp

Critical
CRITICAL RISK
CVSS Score: 9.6
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
29 days ago
September 08, 2026 at 06:32 PM UTC
DeepSeek Harness contains an authentication bypass vulnerability in local HTTP control-plane API
0.0.1-rc.1 - 0.1.1-rc.2
0.0.1-rc.1 - 0.1.1-rc.2

Summary

DeepSeek Harness contains an authentication bypass vulnerability in local HTTP control-plane API

Details

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key.

Timeline

Published
29 days ago
September 08, 2026 at 06:32 PM UTC
Last Modified
7 hours ago
October 07, 2026 at 09:00 PM UTC