DeepSeek Harness Exposed to High-Risk Vulnerability
3 hour ago / Read about 0 minute
Author:小编   

QiAnXin Threat Intelligence Center disclosed that DeepSeek Harness (DSH) contains an unauthorized remote code execution vulnerability, numbered QVD‑2026‑57410, rated as critical with a CVSS 3.0 score of 9.8. The vulnerability's POC has been made public. The affected version is 0.1.1‑rc.2. The vulnerability stems from flaws in the platform's validation of the HTTP Host request header, allowing attackers to bypass the /api trust boundary and execute arbitrary system commands. Exploitation conditions include exposing the management API to the public internet, failing to strictly validate the Host header, and the attacker possessing an external service accessible to the target. Currently, no in-the-wild exploitation has been observed. Affected objects are all deployment instances that expose the management API to the public internet without configuring Host header access controls. Security agencies recommend isolating the management API port from the public internet, allowing access only from trusted internal network IPs, and configuring strict Host header validation rules at the reverse proxy layer. Additionally, they advise promptly upgrading to the patched version.

  • C114 Communication Network
  • Communication Home
7 X 24 Track global technological trends
Hot Topic