跳到正文
dsh-market 浏览插件 GitHub EN

ruanhaodong-tt/dsh-security-guard

DSH 运行时安全守卫:配置加载导入约束、HTTP Host 头校验、附带 VM 沙箱逃逸源码补丁(4 个 CVE)。AI 辅助制作。

Star 数 ★ 0 分类 安全与权限 收录于 2026-09-05

安装

在 DeepSeek Harness 里通过 dsh-market 安装

dsh plugin --profile web add dshmarket

或使用命令行

dsh plugin --profile web add github:ruanhaodong-tt/dsh-security-guard

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络。请先审阅源码,并尽量锁定 commit(github:owner/repo#sha)。

README

AI-assisted production. Vulnerability triage, patch implementation, and plugin code were produced by an AI coding assistant (TraeWork / Trae) under human supervision. / 漏洞定位、补丁代码与插件实现均由 AI 编程助手(TraeWork / Trae)在人工监督下完成。

A runtime security guard plugin for DeepSeek Harness (DSH) that applies defense-in-depth measures at the Cordis plugin layer. It does not modify the original source code — instead, it shadows runtime methods and intercepts HTTP requests to replicate the fixes from the DSH Security Patch.

DSH 运行时安全守卫插件,在 Cordis 插件层施加纵深防御。不修改原始源码——通过运行时方法遮蔽与 HTTP 请求拦截来复制安全补丁的修复语义。

Security Coverage / 安全覆盖

CVE Vulnerability / 漏洞类型 Plugin Coverage / 插件覆盖 Status / 状态
QVD-2026-52631 Config loader arbitrary code execution / 配置加载任意代码执行 Shadows ctx.loader.import to validate builtins, confine relative imports, and reject path-like bare specifiers Full / 完整
QVD-2026-57410 HTTP Host header forgery RCE / Host 头伪造远程代码执行 prependListener on http.Server rejects forged loopback Host claims from non-loopback peers Full / 完整
QVD-2026-52644 VM sandbox exec escape / VM 沙箱 exec 逃逸 Cannot be covered by a plugin. The execView sanitizer lives in a VM-internal closure. Apply the source patch. Not covered / 无法覆盖
QVD-2026-52646 Prompt injection chain sandbox escape / 提示注入链式沙箱逃逸 Cannot be covered by a plugin. The service deny-list is in the sandbox context factory. Apply the source patch. Not covered / 无法覆盖

Important Caveat / 重要说明

The plugin cannot fix QVD-2026-52644 and QVD-2026-52646 because those mitigations are in VM-internal closures and the sandbox context factory — code paths that no Cordis plugin can intercept. You must apply the source patch for full protection.

插件无法修复 QVD-2026-52644 和 QVD-2026-52646,因为这两处修复在 VM 内部闭包和沙箱上下文工厂中——Cordis 插件无法触及这些路径。必须应用源码补丁以获得完整防护。

Installation / 安装

dsh plugin add ruanhaodong-tt/DSH-Security-Patch

Or add to your profile's cordis.patch.yml:

- insert:
    - id: dsh-security-core
      name: dsh-security-guard/core
      inject: [loader]

    - id: dsh-security-web
      name: dsh-security-guard/web
      inject: [webServer]

Configuration / 配置

The web guard accepts an optional trustedHosts array for non-loopback authorities that should be allowed:

- insert:
    - id: dsh-security-web
      name: dsh-security-guard/web
      inject: [webServer]
      config:
        trustedHosts: ["harness.internal:3080"]

Verification / 验证

The plugin logs its activation on startup:

[INFO] dsh-security-core: ctx.loader.import shadowed (QVD-2026-52631)
[INFO] dsh-security-web: HTTP Host guard active (QVD-2026-57410)

You can also verify by sending a forged Host header:

curl -H "Host: localhost:3080" http://<public-ip>:3080/api/  # should return 403

License / 许可证

MIT © 2026 一条大咸鱼

Disclosure / 声明

This plugin was produced with AI assistance. It is not an official patch from DeepSeek, and has not been audited by the upstream. Use at your own risk.

本插件由 AI 辅助制作,并非 DeepSeek 官方补丁,未经上游审计。请自行评估风险后使用。

内容来自项目 README(GitHub)↗

评论

评论存放在 GitHub Discussions。用 GitHub 账号登录后可发表评论或点表情。