Finding / deepseek-harness

2026-09-21-deepseek-harness-security-fixes-a-bubblewrap-escape-via-proc-safety-md-now-says-nothing-is-audited

Security fixes: a Bubblewrap escape via /proc; SAFETY.md now says nothing is audited. On Linux, rc.8 and 0.1.0 builds let a sandboxed process reach the host filesystem through another process’s /proc/<pid>/root. The fix shipped as a release-note line with no advisory.

Channel: preview-or-beta. Half: defect. Date: 2026-08-21 (fix), 2026-08-27 (notice).

Operator consequence: Anyone on rc.8 or rc.7 with the Linux Bubblewrap sandbox should upgrade to >= 0.1.1-rc.1 and treat earlier sandboxed runs as unconfined. Read SAFETY.md as the vendor’s own posture: the sandbox is advisory. A disposable VM is the recommended boundary, in their words.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-deepseek-harness-security-fixes-a-bubblewrap-escape-via-proc-safety-md-now-says-nothing-is-audited

Profile citations

Source links

Primary links, including exact changelog lines when available.