在 deepseek-ai 开发的 deepseek-harness(版本不超过 0.1.7-rc.2)中发现了一个安全漏洞。受影响的组件为 Landlock Backend,具体涉及文件 packages/sandbox/sandbox-local/src/profiles.ts 中的某个未知函数。该漏洞可能导致隔离或沙箱机制失效,无法实现应有的隔离或分区保护。 攻击者必须在本地执行利用操作。该漏洞的利用方法已被公开,攻击者可据此进行攻击。建议尽快应用补丁以修复此问题。 尽管厂商在漏洞披露初期已被联系,但至今未作
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| deepseek-ai | deepseek-harness | 0.1.7-rc.0 |
affected |
0.1.7-rc.1 |
affected | ||
0.1.7-rc.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| deepseek-ai | deepseek-harness | 0.1.7-rc.0 |
cpe:2.3:a:deepseek-ai:deepseek-harness:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101102 | 6.3 MEDIUM | deepseek-ai deepseek-harness Code Mode Sandbox run_code sandbox |
| CVE-2026-101131 | 3.3 LOW | deepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decis |
No comments yet