Switch language한국어
Back to the list

QiAnXin Discloses Critical Remote-Code-Execution Flaw in DeepSeek Harness

TL;DR AI

Key summary

2 min read
  1. QiAnXin disclosed CVE-equivalent QVD-2026-57410, a critical unauthenticated RCE flaw in DeepSeek Harness 0.1.1-rc.2.

  2. Weak HTTP Host header validation can let attackers bypass trust controls, call internal methods, and execute arbitrary commands.

  3. Public proof-of-concept code is available; exposed deployments should be patched immediately and restricted with access controls.

Read the original