行业精选72°

奇安信披露DeepSeek Harness严重远程代码执行漏洞

QiAnXin Discloses Critical Remote-Code-Execution Flaw in DeepSeek Harness

精选理由

奇安信发现DeepSeek Harness重大漏洞,CVSS评分高达9.8,赶紧了解修复方法!

AI 摘要

奇安信威胁情报中心发现DeepSeek Harness存在未经身份验证的远程代码执行漏洞(CVSS评分9.8),漏洞源于HTTP Host-header验证缺陷,已公开漏洞概念验证代码。

原文 · pandaily

QiAnXin Discloses Critical Remote-Code-Execution Flaw in DeepSeek Harness

QiAnXin Threat Intelligence Center disclosed an unauthenticated remote-code-execution vulnerability in DeepSeek Harness (CVSS 9.8), from flawed HTTP Host-header validation, with proof-of-concept code already public.