CVE-2026-101078
CVE-2026-101078 is a medium-severity vulnerability with a CVSS 3.x base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-653.
Key facts
- Severity: Medium (CVSS 3.x base score 6.3)
- CVSS v2: 4.3
- CVSS v4: 1.9
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-653
- Published:
- Last modified:
Description
A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.
Frequently asked questions
- What is CVE-2026-101078?
- A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.
- How severe is CVE-2026-101078?
- CVE-2026-101078 has a CVSS 3.x base score of 6.3, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-101078 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-101078?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-101078 published?
- CVE-2026-101078 was published on 2026-09-28.
References
- https://github.com/Ruoyyy/My_vulnerable/blob/main/SECURITY-MOUNT-ESCAPE.en.md
- https://vuldb.com/cve/CVE-2026-101078
- https://vuldb.com/submit/929381
- https://vuldb.com/vuln/410949
- https://vuldb.com/vuln/410949/cti
Other CWE-653 vulnerabilities
- CVE-2026-4692 — Critical (CVSS 10.0): Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR…
- CVE-2026-63071 — Critical (CVSS 9.8): Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate…
- CVE-2026-53421 — Critical (CVSS 9.8): Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate…
- CVE-2026-53405 — Critical (CVSS 9.8): Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate…
- CVE-2025-1974 — Critical (CVSS 9.8): A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access…
- CVE-2024-33768 — Critical (CVSS 9.8): lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.