DeepSeek Harness是中国DeepSeek公司的一款信息化产品。 DeepSeek Harness 0.1.2-alpha.1之前版本存在输入验证错误漏洞,该漏洞源于其本地HTTP控制面API仅验证客户端提供的Host标头值而非实际TCP连接来源,导致身份验证绕过,攻击者可通过提供伪造的Host标头获取完全代理控制权,调用具有危险全访问权限的特权命令(如commands/execute)、将会话审批策略升级为无限制执行,并可无凭据检索所有存储的对话。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DeepSeek | DeepSeek Harness | < 0.1.2-alpha.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| DeepSeek | DeepSeek Harness | 0 ~ 0.1.2-alpha.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet