CVE-2026-101132 | DeepSeek deepseek-harness up to 0.1.7-rc.2 Bundle Patch profile.ts loadProfile dsh.bundle.patch path traversal (ID 3354)
A vulnerability was found in DeepSeek deepseek-harness up to 0.1.7-rc.2 and classified as problematic. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of the component Bundle Patch Handler. The manipulation of the argument dsh.bundle.patch results in path traversal.
This vulnerability was named CVE-2026-101132. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More