The fence around the sandbox was a request header, and the agent inside sent one
2026-09-09Security
CVE-2026-82533 lets any local process turn off DeepSeek Harness's file sandbox and approval prompts with three POST requests. The check in the way read the Host header, which the caller supplies. Browsers will not forge it. A coding agent running inside the sandbox is not a browser.