security: upgrade DeepSeek Harness past CVE-2026-82533 #14
Labels
No labels
accessibility
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
security
testing
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/agentProlog#14
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
AgentProlog
mastercurrently pins the DeepSeek Harness 0.1.1-rc.2 release train inpackages/agentprolog/package.json,pnpm-lock.yaml, andpackages/agentprolog/src/compatibility.ts.CVE-2026-82533 affects DeepSeek Harness 0.1.1-rc.2 and earlier. A sandboxed coding agent could reach the Harness local control plane and mutate its own session to
danger-full-access, disabling the file sandbox and approval prompts. The upstream fix adds authenticated access to the Harness control plane.Required fix
@deepseek-ai/dsh-*direct dependencies used by AgentProlog to0.1.2-rc.1(or a later explicitly reviewed fixed release).latestdist-tags.SUPPORTED_HARNESSto version0.1.2-rc.1and upstream tag commita66e4702047846cdaa10c66c9d3df3951f5ea70d(dsh-v0.1.2-rc.1).nix flake checkon the upgraded train.Acceptance criteria
0.1.1-rc.2DeepSeek Harness packages remain in the AgentProlog dependency graph.0.1.1-rc.2host identity is rejected before runtime/plugin activation.0.1.2-rc.1+ commita66e4702047846cdaa10c66c9d3df3951f5ea70dis accepted.References
dsh-v0.1.2-rc.1/a66e4702047846cdaa10c66c9d3df3951f5ea70d