Skip to content
cve — cve-2026-82533

grep -rl "CVE-2026-82533" ./articles

CVE-2026-82533

CVE-2026-82533 lets any local process turn off DeepSeek Harness's file sandbox and approval prompts with three POST requests. The check in the way read the Host header, which the caller supplies. Browsers will not forge it. A coding agent running inside the sandbox is not a browser.

1 article — 2026-09-09

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered