One week in, DeepSeek Harness faced its first real test — not a competitor, but a critical security vulnerability. That's a backhanded good sign: it means enough people are running it that the researchers showed up. But it also means the honeymoon is over, and the conversation shifts from "how fast" to "how safe".
The big story: a critical RCE at CVSS 9.8
Around August 24, security researchers disclosed an unauthenticated remote code execution (RCE) vulnerability in DeepSeek Harness, rated CVSS 9.8 — critical. Against the backdrop of "everyone installs it overnight," this is Harness's first genuine security crisis.
We won't walk through exploit details here. The practical takeaway is blunt: if you installed it to try it out, don't rush it to production. Wait for the official patch and pin a patched version. The "it works, but you have to watch it" line has now extended from features to security.
The week, in order
rc.7 ships: plugin settings cards, PTC mode, and a `low` reasoning effort for DeepSeek models.
rc.8 lands: 14 changes, native image input — the "three updates a week" cadence takes shape.
V4-Flash-Vision-Exp launches: multimodal vision at Flash pricing, images capped at 384 tokens.
Peak/off-peak billing adjusts: weekends now charge entirely at the off-peak rate.
The critical RCE (CVSS 9.8) is disclosed; Codex Harness is open-sourced.
Three threads worth following
Velocity. rc.8's native image input is the headline feature — agents can finally see screenshots, diagrams, and documents. But the cadence is the deeper signal: three releases a week means real momentum, and a moving target for plugin authors (we covered the rc.7 keyed-slot migration here).
Positioning. Harness now runs Claude Code and Codex as sub-agents — explicitly aiming to be the scheduling layer above every agent, not a rival to any one of them.
Ecosystem. Star count passed 150K, enterprise data providers like Qichacha are adapting, and Codex Harness open-sourced — the "Android vs iOS" framing just got another data point.
Our take
The RCE is a gate Harness had to pass through. Explosive growth means install base, and install base means security researchers — that's the sign of a maturing ecosystem, but you eat the security scare before you get the maturity. Our stance hasn't changed: play with it, internalize the plugin mindset, and hold production until the patch is in and your version is pinned.
On cadence: "three updates a week" is a double-edged sword. The momentum is real, but so is the churn — plugin authors shouldn't treat "it worked yesterday" as a deployment strategy.
One line: Harness has moved from a launch event to an operating system — and the question is no longer whether it's fast enough, but whether it's steady enough.