DeepSeek Harness CVE let agents disable their own sandbox
OX Security reported CVE-2026-82533 (CVSS 9.4) in DeepSeek Harness: spoofing the Host header let agents or remote attackers escalate to danger-full-access, escape the OS sandbox, and pull stored conversations. Fixed in 0.1.2-alpha.1; upgrade if you still run an older build.