DeepSeek Harness Trusted a Header the Caller Wrote. shell.online 0.16.1 Stops Trusting Its Relay on Replays and Read-Only
This story is from 2026-09-17. It is preserved in the archive; the latest stories are on the live feed.
On September 8, OX Security published CVE-2026-82533 in DeepSeek Harness , CVSS 9.4. The harness gated its local agent-control API on 127.0.0.1:3080 with one function, isTrustedApiRequest , which read the Host request header and, in OX's words, "never compared that value with the connection's actua…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-17 16:05 · DEV Community — AI
DeepSeek Harness Trusted a Header the Caller Wrote. shell.online 0.16.1 Stops Trusting Its Relay on Replays and Read-Only