CVE-2026-101132
Received Received - Intake

Path Traversal in DeepSeek deepseek-harness

Vulnerability report for CVE-2026-101132, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of the component Bundle Patch Handler. The manipulation of the argument dsh.bundle.patch results in path traversal. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
deepseek deepseek-harness to 0.1.7-rc.2 (inc)
deepseek deepseek_harness to 0.1.7-rc.2 (inc)
deepseek deepseek_harness to 0.1.0-rc.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101132 is a path traversal vulnerability in DeepSeek Harness up to version 0.1.7-rc.2. It occurs in the loadProfile function of profile.ts where the dsh.bundle.patch argument is not properly validated. This allows attackers to manipulate the path to access files outside the intended bundle directory using ../ segments or absolute paths.

Detection Guidance

Check for installed DeepSeek Harness versions up to 0.1.0-rc.5. Inspect bundle manifests for malicious dsh.bundle.patch values containing ../ or absolute paths. Monitor diagnostic command outputs for unexpected file content leaks.

Impact Analysis

An attacker could exploit this to read sensitive files like credentials or configuration data by installing a malicious package with a crafted dsh.bundle.patch value. The vulnerability is triggered when using diagnostic commands like --dump-config or --dump-default-config, which output the contents of traversed files to stdout.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive files, potentially exposing personal data or credentials. This may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information if such data is compromised.

Mitigation Strategies

Upgrade DeepSeek Harness to a patched version. Validate dsh.bundle.patch paths to ensure they stay within bundle directories. Restrict bundle installation sources to trusted repositories. Remove any malicious bundles with crafted patch values.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101132. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart