CVE-2026-101102: Sandbox Issue in deepseek-ai deepseek-harness
A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in sandbox issue. The attack can be executed remotely. The vendor's own code, SAFETY.md, and design notes all explicitly state the worker is "containment, not a security boundary". The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability affects the run_code function within the Code Mode Sandbox of deepseek-ai deepseek-harness up to version 0.1.0-rc.7. The issue allows remote attackers to manipulate the sandbox environment, leading to a sandbox containment failure. The vendor's documentation clarifies that the sandbox is not intended as a security boundary, which implies limited protection against exploitation. There is no vendor response or patch available at this time.
Potential Impact
The vulnerability allows remote attackers to bypass sandbox containment controls in the affected versions of deepseek-harness. This could lead to unauthorized code execution or other actions outside the intended sandbox environment. However, the vendor's own statements indicate the sandbox is not a security boundary, which may limit the severity of impact in some deployment contexts.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should be aware that the sandbox is not designed as a security boundary and should not rely on it for strong isolation. Until a patch or official guidance is provided by the vendor, consider restricting exposure of the affected component to untrusted users or networks.
CVE-2026-101102: Sandbox Issue in deepseek-ai deepseek-harness
Description
A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in sandbox issue. The attack can be executed remotely. The vendor's own code, SAFETY.md, and design notes all explicitly state the worker is "containment, not a security boundary". The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 5.3medium
Affected software
deepseek-ai
deepseek-harness
pkg:npm/deepseek-ai/deepseek-harnesscpe:2.3:a:deepseek-ai:deepseek-harness:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects the run_code function within the Code Mode Sandbox of deepseek-ai deepseek-harness up to version 0.1.0-rc.7. The issue allows remote attackers to manipulate the sandbox environment, leading to a sandbox containment failure. The vendor's documentation clarifies that the sandbox is not intended as a security boundary, which implies limited protection against exploitation. There is no vendor response or patch available at this time.
Potential Impact
The vulnerability allows remote attackers to bypass sandbox containment controls in the affected versions of deepseek-harness. This could lead to unauthorized code execution or other actions outside the intended sandbox environment. However, the vendor's own statements indicate the sandbox is not a security boundary, which may limit the severity of impact in some deployment contexts.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should be aware that the sandbox is not designed as a security boundary and should not rely on it for strong isolation. Until a patch or official guidance is provided by the vendor, consider restricting exposure of the affected component to untrusted users or networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-28T02:59:05.372Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abaaf79f7a7c5410609047a
Added to database: 09/28/2026, 18:18:33 UTC
Last enriched: 09/28/2026, 18:32:49 UTC
Last updated: 09/29/2026, 02:45:42 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.