CVE-2026-101078
Received Received - Intake

Improper Isolation in DeepSeek Harness Landlock Backend

Vulnerability report for CVE-2026-101078, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
deepseek-ai deepseek-harness to 0.1.7-rc.2 (inc)
deepseek-ai deepseek-harness 0.1.7-rc.2
deepseek-ai deepseek-harness 0.1.0-rc.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101078 is a sandbox escape vulnerability in deepseek-harness up to 0.1.7-rc.2. It allows a locally executed process to bypass isolation by manipulating mount operations. The issue stems from missing the --unshare-user flag in the bwrap backend and improper capability handling in the landlock backend. This enables processes running as root to remount filesystems as read-write, modify host files, or perform other privileged mount operations, effectively breaking the sandbox containment.

Detection Guidance

Check if deepseek-harness is running as root and inspect the bwrap profile in packages/sandbox/sandbox-local/src/profiles.ts for missing --unshare-user flag. Look for processes with CAP_SYS_ADMIN capability in mount namespaces using commands like ps aux | grep deepseek or grep CapEff /proc/[0-9]*/status.

Impact Analysis

If you run deepseek-harness as root, this vulnerability could allow an attacker with local access to escape the sandbox and gain full control over the host system. This includes writing or deleting any file, installing malware, or altering system configurations. Non-root users are not affected due to kernel restrictions preventing such operations.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating confidentiality and integrity requirements in GDPR and HIPAA. Organizations using deepseek-harness in root contexts may fail compliance audits due to insufficient process isolation and privilege management controls.

Mitigation Strategies

Update deepseek-harness to a patched version that includes --unshare-user in the bwrap profile. If no patch is available, manually add --unshare-user to the bwrap command and ensure the landlock backend drops unnecessary privileges or uses a user namespace.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101078. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart