Finding / deepseek-harness
2026-09-21-deepseek-harness-security-fixes-a-bubblewrap-escape-via-proc-safety-md-now-says-nothing-is-audited
Security fixes: a Bubblewrap escape via /proc; SAFETY.md now says nothing is audited. On Linux, rc.8 and 0.1.0 builds let a sandboxed process reach the host filesystem through another process’s /proc/<pid>/root. The fix shipped as a release-note line with no advisory.
Channel: preview-or-beta. Half: defect. Date: 2026-08-21 (fix), 2026-08-27 (notice).
Operator consequence: Anyone on rc.8 or rc.7 with the Linux Bubblewrap sandbox should upgrade to >= 0.1.1-rc.1 and treat earlier sandboxed runs as unconfined. Read SAFETY.md as the vendor’s own posture: the sandbox is advisory. A disposable VM is the recommended boundary, in their words.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-deepseek-harness-security-fixes-a-bubblewrap-escape-via-proc-safety-md-now-says-nothing-is-audited
Profile citations
- deepseek-harness / claim / bubblewrap-escape-safety-md
Source links
Primary links, including exact changelog lines when available.