Official company update
DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
GitLab·about.gitlab.com·
What the source says
GitLab's Threat Research Group discovered a command execution vulnerability ( GHSA-grg2-7gc6-36m6 , CVE-2026-102437 ) in DeepSeek-Reasonix Studio, a desktop git client designed for developers pairing with AI coding assistants. The flaw, called ConfigPoisoning, could allow attacker-supplied code to execute when a developer views a file's diff. To address this
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about GitLab
Official · about.gitlab.comTrack organization-wide security risk in one dashboardOfficial · about.gitlab.comEvery artifact your teams ship, assembled right the first timeOfficial · about.gitlab.comDependency Firewall: Block risky packages before the buildOfficial · about.gitlab.comGitLab Transcend: Speed you can trust, all the way to production