QiAnXin Discloses Critical Remote-Code-Execution Flaw in DeepSeek Harness

TL;DR AI
2 min readKey summary
QiAnXin disclosed CVE-equivalent QVD-2026-57410, a critical unauthenticated RCE flaw in DeepSeek Harness 0.1.1-rc.2.
Weak HTTP Host header validation can let attackers bypass trust controls, call internal methods, and execute arbitrary commands.
Public proof-of-concept code is available; exposed deployments should be patched immediately and restricted with access controls.


