AINewsnow

DeepSeek Harness Trusted a Header the Caller Wrote. shell.online 0.16.1 Stops Trusting Its Relay on Replays and Read-Only

This story is from 2026-09-17. It is preserved in the archive; the latest stories are on the live feed.

On September 8, OX Security published CVE-2026-82533 in DeepSeek Harness , CVSS 9.4. The harness gated its local agent-control API on 127.0.0.1:3080 with one function, isTrustedApiRequest , which read the Host request header and, in OX's words, "never compared that value with the connection's actua…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-17 16:05 · DEV Community — AI
    DeepSeek Harness Trusted a Header the Caller Wrote. shell.online 0.16.1 Stops Trusting Its Relay on Replays and Read-Only

More stories

  1. Cactus Needle 3: A Sliceable 8-29MB Automation Foundation Model That Matches DeepSeek v4 Flash — r/LocalLLaMA
  2. DeepSeek’s Insane New Architecture — Two Minute Papers
  3. Jina AI Releases jina-ocr-v1: A 3.4B MoE Document Parser With Built-In Speculative Decoding for Low-Budget GPUs — MarkTechPost
  4. Gemini 4 is good enough - JUST RELEASE IT — r/GeminiAI
  5. Own 1 dashboard for ChatGPT, Gemini, Claude, and more for only $54.97 — Mashable AI
  6. I enjoyed the daily HF papers today — r/LocalLLaMA
  7. Engrams Embedding Entendre: Codesign for Efficient DRAM/SSD Offloading — SemiAnalysis
  8. Coming soon...... Optimized for DEEPSEEK Flash.... Though model Agnostic.... message me to test.... cem888.ai — r/huggingface

Get the daily brief of stories like this at 6:30 every morning →