DeepSeek AI Coding Tool Flaw Let Agents Turn Off Their Own Security Sandbox
DeepSeek Harness, an open-source tool for running AI coding agents on a developer's machine, contained a flaw that let a sandboxed agent switch off its own protective sandbox. The tool normally runs an agent's commands inside an operating-system sandbox so it cannot write files outside its assigned workspace. Researchers found that an agent could call the tool's own local web interface and switch its session into a mode called danger-full-access, removing the sandbox and any approval prompts, all with a single command.
Security firm OX Research reported the issue, tracked as CVE-2026-82533 and rated 9.4 out of 10 by VulnCheck. The flaw worked because the tool's local interface had no authentication; it checked only a request header, not where the connection came from, and a comment in the code admitted this was 'not an auth layer'. The tool also handed the agent's shell the address of that interface and its session ID, making the escape easier to trigger. Attackers could exploit this by embedding malicious text in a file that the agent later read, prompting it to make the disabling call itself.
DeepSeek fixed the flaw in an update released on August 27. Until then, default installations of the tool were affected, meaning agents processing untrusted files could potentially write data outside their intended workspace without any warning to the user.