DeepSeek Harness Sandbox Escape Lets AI Agents Disable Their Own Confinement
CVE-2026-82533 represents the first confirmed instance where an AI agent runtime sandbox has served as the direct attack surface for a vulnerability. Discovered by Nir Zadok and Moshe Siman Tov Bustan of OX Security, the flaw exists in DeepSeek Harness (dsh), an open-source, local-first coding agent tool that reached over 215,000 GitHub stars within weeks…