漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
Vulnerability Description
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to escape its own OS sandbox, escalate to unconfined execution, and disable the approval prompt. When the port is externally reachable via tunnel, SSH forward, or reverse proxy, a remote attacker can exploit the same flaw to create sessions, execute arbitrary commands, and exfiltrate stored conversation transcripts without credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
在安全决策中依赖未经信任的输入
Vulnerability Title
DeepSeek Harness 输入验证错误漏洞
Vulnerability Description
DeepSeek Harness是中国DeepSeek公司的一款信息化产品。 DeepSeek Harness 0.1.2-alpha.1之前版本存在输入验证错误漏洞,该漏洞源于其本地HTTP控制面API仅验证客户端提供的Host标头值而非实际TCP连接来源,导致身份验证绕过,攻击者可通过提供伪造的Host标头获取完全代理控制权,调用具有危险全访问权限的特权命令(如commands/execute)、将会话审批策略升级为无限制执行,并可无凭据检索所有存储的对话。
CVSS Information
N/A
Vulnerability Type
N/A