CVE-2026-101131 | deepseek-ai deepseek-harness up to 0.1.5-rc.3 dsh index.ts E2B_API_KEY reliance on untrusted inputs in a security decision
A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.5-rc.3 and classified as problematic. Impacted is an unknown function of the file packages/e2b/e2b/src/index.ts of the component dsh. The manipulation of the argument E2B_API_KEY leads to reliance on untrusted inputs in a security decision.
This vulnerability is uniquely identified as CVE-2026-101131. Local access is required to approach this attack. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More