Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/deepseek-harness

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in deepseek-ai deepseek-harness up to version 0.1.5-rc.3 allows local attackers to manipulate the E2B_API_KEY argument, causing reliance on untrusted inputs in a security decision. The issue affects an unknown function in the file packages/e2b/e2b/src/index.ts of the dsh component. Exploit code is publicly available. The vendor has not responded to disclosure attempts. The vulnerability has a low severity score of 3.3 CVSS and requires local access for exploitation.

Join the discussion

A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of the component Bundle Patch Handler. The manipulation of the argument dsh.bundle.patch results in path traversal. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

A vulnerability exists in deepseek-ai deepseek-harness up to version 0.1.0-rc.7 affecting the run_code function within the Code Mode Sandbox component. This vulnerability allows remote manipulation resulting in a sandbox issue. The vendor explicitly states that the worker is intended for containment and not as a security boundary. The vendor has not responded to disclosure attempts. The CVSS score is 6.3, indicating a medium severity level.

Join the discussion

A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in sandbox issue. The attack can be executed remotely. The vendor's own code, SAFETY.md, and design notes all explicitly state the worker is "containment, not a security boundary". The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

A vulnerability in deepseek-ai deepseek-harness up to version 0.1.7-rc.2 allows local attackers to manipulate an unknown function in the Landlock Backend component, leading to improper isolation or compartmentalization. The vulnerability has a CVSS score of 6.3 and was publicly disclosed. The vendor has not responded or provided a patch. Exploitation requires local access and no known exploits are currently in the wild.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:npm/deepseek-harness
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses