在 deepseek-ai 发布的 deepseek-harness 版本(最高至 0.1.0-rc.7)中发现了一个漏洞。受影响的组件是“代码模式沙箱”(Code Mode Sandbox)中的 函数。该漏洞可导致沙箱被突破,攻击者可以远程发起攻击。 尽管该漏洞存在,但供应商在其自有代码、SAFETY.md 文件以及设计说明中均明确指出,该沙箱的设计目标是提供“隔离环境,而非安全边界”。供应商已在早期被通知此漏洞披露,但至今未作出任何回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| deepseek-ai | deepseek-harness | 0.1.0-rc.0 |
affected |
0.1.0-rc.1 |
affected | ||
0.1.0-rc.2 |
affected | ||
0.1.0-rc.3 |
affected | ||
0.1.0-rc.4 |
affected | ||
0.1.0-rc.5 |
affected | ||
0.1.0-rc.6 |
affected | ||
0.1.0-rc.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| deepseek-ai | deepseek-harness | 0.1.0-rc.0 |
cpe:2.3:a:deepseek-ai:deepseek-harness:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101078 | 6.3 MEDIUM | deepseek-ai deepseek-harness Landlock Backend profiles.ts isolation |
| CVE-2026-101131 | 3.3 LOW | deepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decis |
No comments yet