Threat intelligence dashboard
CVE-2026-101131medium

deepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a security decision

A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the file packages/e2b/e2b/src/index.ts of the component dsh. The manipulation of the argument E2B_API_KEY leads to reliance on untrusted inputs in a security decision. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk score

4.8

CVSS 4.0

Vendor
deepseek-ai
Product
deepseek-harness
CWE
CWE-807, CWE-20
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

deepseek-harness

deepseek-ai

Version / rangeStatusType
0.1.5-rc.0affected—
0.1.5-rc.1affected—
0.1.5-rc.2affected—
0.1.5-rc.3affected—

Technical metrics

4.8

CVSS 4.0

Severity
medium
Source
VulDB
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

3.3

CVSS 3.1

Severity
low
Source
VulDB
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C

3.3

CVSS 3.0

Severity
low
Source
VulDB
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C

1.7

CVSS 2.0

Severity
low
Source
VulDB
Vector
AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C