Trending:

GitLab reveals ConfigPoisoning in DeepSeek-Reasonix could let attackers run code when developers view diffs

Graphic illustrating poisoned repository configuration enabling code execution
TechStaged-owned

Summary

  • GitLab's Threat Research Group identified a critical command execution vulnerability in DeepSeek-Reasonix Studio, named ConfigPoisoning.
  • The flaw could allow attacker-supplied code to execute when a developer views a file’s diff.
  • The vulnerability is tracked as GHSA-grg2-7gc6-36m6 and CVE-2026-102437.

GitLab's Threat Research Group disclosed a critical command execution vulnerability in DeepSeek-Reasonix Studio, dubbed ConfigPoisoning. The flaw could allow attacker-supplied code to execute when a developer views a file’s diff in a repository configured in certain ways. The issue is tracked as GHSA-grg2-7gc6-36m6 and CVE-2026-102437.

DeepSeek-Reasonix is the first such tool disclosed in full, and GitLab notes that multiple widely used coding agents may be susceptible to similar vulnerabilities that execute commands from a repository’s own configuration files (.git/config and .gitattributes).

  • The root cause involves how certain git config keys are exercised during diff rendering. While DeepSeek-Reasonix hardens several keys, a gap remained in filter.<driver>.clean, which can be invoked per file via .gitattributes.

HOW THE ATTACK WORKS IN PRACTICE

According to the disclosure, a repository can carry a .gitattributes entry that assigns a filter driver (for example, named pwn) and a corresponding clean command defined in .git/config by the repository author. When a developer opens a diff for a file (such as secret.bin), DeepSeek-Reasonix runs its diff rendering with several hardening flags, but the poisoned filter can still execute the attacker’s command during the diff construction. TechStaged has also covered GitLab Credits Bring Usage-Based Pricing to Duo Agent Platform.

  • The attack path can generate the comparison blob twice (once per diff side), exploiting the filter invocation during diff rendering.
  • The vulnerability can be triggered whether the developer clones the repo via direct methods or when a rogue tool already has filesystem access and writes a poisoned .git/config into a cloned repo.

PATCH, MITIGATION, AND PRACTICAL GUIDANCE

GitLab urges updating to DeepSeek-Reasonix Studio 2.21.0 or DeepSeek Reasonix npm 1.39.3 to address the flaw. The guidance emphasizes that if tools shell out to git, practitioners should override every relevant git key on every call (not just the ones that were hardened) or avoid invoking git’s filter/textconv machinery for diffing altogether.

  • Override keys such as core.fsmonitor, core.pager, core.editor, core.hooksPath, diff.external, core.sshCommand, and filter.<driver>.clean across all .gitattributes entries.
  • Prefer in-process diffing or reading blobs with git cat-file or git show when byte-level content suffices.
  • If diffing is necessary, test configurations against hostile config pairs before shipping.
  • Be aware that a compromised coding agent with developer permissions can write poisoned configuration into an already-cloned repo, bypassing some containment.

CONTEXT, SCOPE, AND WHAT IT MEANS FOR TEAMS

GitLab notes that this is not an isolated bug; the pattern of attacker-controlled commands being executed from a repository’s own configuration file has been observed in other agent tools. Repositories hosted on GitLab itself are not affected when cloning occurs over HTTPS or SSH because local configuration files are not transferred in that workflow.

  • The vulnerability primarily affects coding agents that wrap or interact with git and rely on per-repository configuration for diff or file-transform steps.
  • DeepSeek-Reasonix is highlighted as the first case disclosed in full, with warnings that similar weaknesses may exist in other agent-enabled development tools.

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.