CVE-2026-108788 | deepseek-ai deepseek-harness up to 0.1.1-rc.2 Sandbox spawn profile sandbox
A vulnerability labeled as problematic has been found in deepseek-ai deepseek-harness up to 0.1.1-rc.2. The impacted element is the function spawn of the component Sandbox. Executing a manipulation of the argument Profile can lead to sandbox issue.
This vulnerability is handled as CVE-2026-108788. It is possible to launch the attack on the local host. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More