DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
- 1. DeepSeek Harness contained a flaw allowing sandboxed AI agents to disable sandbox isolation with a single command.
- 2. VulnCheck assigned CVE-2026-82533 to the DeepSeek Harness vulnerability, giving it a 9.4 out of 10 severity rating.
- 3. DeepSeek patched the vulnerability by requiring one-time token authentication and signed cookies for interface calls.
Catch up on The Hacker News articles in minutes
skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 9th September 2026.