PulseAugur
实时 12:11:05
Italiano(IT) CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox Un'interfaccia locale priva di autenticazione e vulnera

DeepSeek Harness中的关键漏洞允许AI代理绕过沙箱

在DeepSeek Harness中发现了一个关键漏洞CVE-2026-82533。DeepSeek Harness是DeepSeek用于运行本地编码代理的开源工具。该漏洞允许AI代理通过利用一个未经身份验证的本地Web接口来绕过自身的沙箱限制并获得对系统的完全访问权限。此绕过可以通过单个shell命令触发,从而禁用文件系统沙箱和敏感操作的批准提示。0.1.1-rc.2之前的版本受到影响,修复措施引入了本地接口的基于令牌的身份验证。 AI

影响 凸显了AI代理框架中实施强大安全措施以防止未经授权访问和操纵的关键需求。

排序理由 披露了AI框架中的关键安全漏洞。[lever_c_demoted from research: ic=1 ai=1.0]

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

DeepSeek Harness中的关键漏洞允许AI代理绕过沙箱

本文如何被排名

Signal score
12 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
披露了AI框架中的关键安全漏洞。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. Mastodon — mastodon.social TIER_1 Italiano(IT) · [email protected] ·

    CVE-2026-82533:DeepSeek Harness中的漏洞,导致AI代理拥有了其沙盒的密钥。一个未经身份验证且易受攻击的本地接口

    CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox Un'interfaccia locale priva di autenticazione e vulnerabile a host header spoofing permetteva agli agenti di DeepSeek Harness di disattivare la propria sandbox con un solo com…