DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
Summary
DeepSeek Harness, an open-source tool for running AI coding agents in a sandbox (an isolated environment where programs can only access certain files), had a critical flaw that let an agent disable its own sandbox protections with a single command. An attacker could trick the agent into calling the tool's web interface to switch to a 'danger-full-access' mode, allowing the agent to write files outside its workspace without approval, though the fix was deployed on August 27.
Solution / Mitigation
Install version 0.1.2-alpha.2 or later from npm. The CVE record names 0.1.2-alpha.1 as fixed (released August 27), but the first fixed release published to npm is 0.1.2-alpha.2 (August 30). The current npm release, 0.1.2-rc.1 (September 3), also carries the fix. If you cannot upgrade, stop the web interface when not in use and remove any tunnel, proxy, or port forward that reaches it.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
First tracked: September 9, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 95%