GitLab's Threat Research Group disclosed a critical command execution vulnerability in DeepSeek-Reasonix Studio, dubbed ConfigPoisoning. The flaw could allow attacker-supplied code to execute when a developer views a file’s diff in a repository configured in certain ways. The issue is tracked as GHSA-grg2-7gc6-36m6 and CVE-2026-102437.
DeepSeek-Reasonix is the first such tool disclosed in full, and GitLab notes that multiple widely used coding agents may be susceptible to similar vulnerabilities that execute commands from a repository’s own configuration files (.git/config and .gitattributes).
- The root cause involves how certain git config keys are exercised during diff rendering. While DeepSeek-Reasonix hardens several keys, a gap remained in filter.<driver>.clean, which can be invoked per file via .gitattributes.
HOW THE ATTACK WORKS IN PRACTICE
According to the disclosure, a repository can carry a .gitattributes entry that assigns a filter driver (for example, named pwn) and a corresponding clean command defined in .git/config by the repository author. When a developer opens a diff for a file (such as secret.bin), DeepSeek-Reasonix runs its diff rendering with several hardening flags, but the poisoned filter can still execute the attacker’s command during the diff construction. TechStaged has also covered GitLab Credits Bring Usage-Based Pricing to Duo Agent Platform.
- The attack path can generate the comparison blob twice (once per diff side), exploiting the filter invocation during diff rendering.
- The vulnerability can be triggered whether the developer clones the repo via direct methods or when a rogue tool already has filesystem access and writes a poisoned .git/config into a cloned repo.
PATCH, MITIGATION, AND PRACTICAL GUIDANCE
GitLab urges updating to DeepSeek-Reasonix Studio 2.21.0 or DeepSeek Reasonix npm 1.39.3 to address the flaw. The guidance emphasizes that if tools shell out to git, practitioners should override every relevant git key on every call (not just the ones that were hardened) or avoid invoking git’s filter/textconv machinery for diffing altogether.
- Override keys such as core.fsmonitor, core.pager, core.editor, core.hooksPath, diff.external, core.sshCommand, and filter.<driver>.clean across all .gitattributes entries.
- Prefer in-process diffing or reading blobs with git cat-file or git show when byte-level content suffices.
- If diffing is necessary, test configurations against hostile config pairs before shipping.
- Be aware that a compromised coding agent with developer permissions can write poisoned configuration into an already-cloned repo, bypassing some containment.
CONTEXT, SCOPE, AND WHAT IT MEANS FOR TEAMS
GitLab notes that this is not an isolated bug; the pattern of attacker-controlled commands being executed from a repository’s own configuration file has been observed in other agent tools. Repositories hosted on GitLab itself are not affected when cloning occurs over HTTPS or SSH because local configuration files are not transferred in that workflow.
- The vulnerability primarily affects coding agents that wrap or interact with git and rely on per-repository configuration for diff or file-transform steps.
- DeepSeek-Reasonix is highlighted as the first case disclosed in full, with warnings that similar weaknesses may exist in other agent-enabled development tools.
RELATED COVERAGE
- GitLab Credits Bring Usage-Based Pricing to Duo Agent Platform
- GPT-6 Astra on GitLab Duo Agent Platform delivers faster runs and fewer tokens
- GitHub Copilot Desktop App Opens to Every Copilot Plan
- Vercel AI SDK HarnessAgent Connects Claude Code, Codex, and Pi Behind One Interface
- Developer Tools articles
SOURCES
- GitLab: DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent Published · Primary source






