GitLab’s Threat Research Group says a flaw in DeepSeek-Reasonix Studio could let a hostile repository run attacker-controlled code when a developer views a file diff. GitLab says fixes are available, and the report points to a wider risk for coding tools that invoke Git on repositories they do not control.
Watch Desk analysis
What happened
GitLab says the vulnerability, named ConfigPoisoning and assigned CVE-2026-102437, affects DeepSeek-Reasonix Studio and its npm package. The trigger is a Git clean filter set through repository attributes and configuration. In the reported attack, viewing a changed file’s diff runs the filter command. GitLab says the issue affected Studio and npm versions before 2.21.0 and 1.39.3 respectively, and that the maintainers accepted the report and shipped a fix. Read GitLab’s technical report.
GitLab says the same class of weakness may affect other coding agents, but this is the first case it is disclosing in full. Its account says more details will follow once fixes are available. That is a warning about a pattern, not evidence that every named or unnamed tool is vulnerable.
Who is affected
- DeepSeek-Reasonix Studio
GitLab recommends updating to version 2.21.0. - DeepSeek Reasonix npm
GitLab recommends updating to version 1.39.3. - Teams building tools around Git
GitLab advises neutralising relevant Git configuration on every invocation, or avoiding Git’s filter and text-conversion machinery where possible. - Developers opening unfamiliar repositories
The report says repository configuration can trigger commands during diff rendering; an ordinary-looking review action is the trapdoor here.
Why it matters
A coding tool can inherit settings controlled by the repository it opens. GitLab says its tested attack runs when a developer views a diff, and explains that a filter configured in .git/config can still execute despite other hardening flags used by the tool. It also describes a route where another agent or process writes poisoned configuration into an already-cloned repository.
That makes this more than a case of trusting a suspicious download. The important boundary is whether a tool running with a developer’s permissions safely handles repository-controlled settings. GitLab says repositories hosted on GitLab are not affected simply by cloning over HTTPS or SSH, because those methods do not transfer local Git configuration files.
Our read
Update the affected Studio or npm package, and treat Git-invoking coding tools as part of your attack surface. GitLab’s disclosure gives maintainers concrete questions to ask about configuration handling; the wider warning deserves attention, but the report does not establish which other agents are affected. Git, it turns out, has more than one way to make a diff interesting.
What to watch
- Which other coding-agent vulnerabilities GitLab discloses after fixes become available.
- Whether affected projects publish their own advisories and patched versions.
- Whether developers of Git-integrated tools explain how they neutralise repository-controlled configuration.
Discussion spark: Should coding tools that run Git on a developer’s machine be expected to neutralise every repository-controlled setting by default, or is that burden properly shared with users and repository hosts?
Sources and evidence
- DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent – GitLab (2 October 2026, 16:52 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.