In the News: September 9, 2026 (Extra)
A DeepSeek Harness flaw let a sandboxed coding agent disable its own sandbox with one unauthenticated call; the fix does not confine reads or network access.
Extra edition
Machine-readable
Download Markdown
Story
DeepSeek Harness let a sandboxed agent switch off its own sandbox
DeepSeek Harness runs an agent's shell commands inside an operating-system sandbox so that work on untrusted files cannot write outside the agent's workspace. VulnCheck scored the flaw 9.4 out of 10 on CVSS 4.0 and classified it as CWE-807,…
Read story →