Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101132 | 2 Deepseek, Deepseek-ai | 2 Deepseek-harness, Deepseek-harness | 2026-09-29 | 3.1 Low |
| A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of the component Bundle Patch Handler. The manipulation of the argument dsh.bundle.patch results in path traversal. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101131 | 1 Deepseek-ai | 1 Deepseek-harness | 2026-09-28 | 3.3 Low |
| A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the file packages/e2b/e2b/src/index.ts of the component dsh. The manipulation of the argument E2B_API_KEY leads to reliance on untrusted inputs in a security decision. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101102 | 1 Deepseek-ai | 1 Deepseek-harness | 2026-09-28 | 6.3 Medium |
| A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in sandbox issue. The attack can be executed remotely. The vendor's own code, SAFETY.md, and design notes all explicitly state the worker is "containment, not a security boundary". The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101078 | 1 Deepseek-ai | 1 Deepseek-harness | 2026-09-28 | 6.3 Medium |
| A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
Page 1 of 1.