DeepSeek AI agent tool flaw lets an agent disable its own sandbox
Researchers at VulnCheck found a flaw in the DeepSeek Harness, a tool that runs an AI agent's commands inside an operating-system sandbox so an agent handling untrusted files cannot write outside its workspace. Through an authentication bypass using a spoofed host header, an attacker needing no credentials or API key can call the tool's own web interface to invoke privileged commands with full-access permissions, raise the session's approval policy to unrestricted execution, and read every stored conversation. In effect, the sandbox meant to contain the agent can be switched off from outside. It is a reminder that an AI agent's isolation is only as strong as the authentication protecting its control interface.
- Check
- If you run the DeepSeek Harness or similar agent-sandboxing tools, restrict and authenticate access to their control interfaces, keep them off untrusted networks, and apply vendor fixes for the host-header authentication bypass.
- Affected
- Deployments using the DeepSeek Harness to sandbox AI agents; an unauthenticated attacker who reaches its control interface can spoof the host header to escalate to full-access command execution and dump conversations.
- Fix
- Authenticate and lock down agent-sandbox control planes, never expose them to untrusted networks, validate host headers, patch the flaw, and design agent isolation assuming the control interface itself is a target.