If you use DeepSeek-Reasonix Studio as your AI-assisted git client, stop and update right now. GitLab’s Threat Research Group disclosed a critical command execution vulnerability (CVE-2026-102437, CVSS 7.8) that can run attacker-controlled code on your machine the moment you view a file diff.
What the bug does
The vulnerability is called ConfigPoisoning. It lives in DeepSeek-Reasonix’s internal/gitcmd wrapper. That wrapper already blocks several dangerous git config keys on every call: core.fsmonitor, maintenance.auto, and it appends --no-ext-diff and --no-textconv to diffs. One key it never touches is filter.<driver>.clean.
Git selects the clean filter per file through .gitattributes, not through a fixed config key, so no deny-list can block it the way the others were blocked. When a developer opens a file’s diff in the desktop app, git invokes that filter to build the comparison blob. The attacker’s command runs, once for each side of the diff, meaning the payload fires twice per diff view.

How delivery works
The poisoned .gitattributes entry survives a clone. The .git/config that defines the malicious filter driver does not. That means the attacker needs a second delivery path: an archive, a synced folder, a CI cache, or a devcontainer build.
There is also a more direct vector for agentic tooling specifically. A rogue, compromised, or prompt-injected coding agent already running on the developer’s machine has filesystem access. It can write the poisoned .git/config directly into an already-cloned, completely normal repository. No archive required. GitLab confirmed the vulnerability at commit ea28602 and the tagged pre-release studio-v2.9.0. It affects both the desktop app and the npm package.
GitLab also notes this is not an isolated case. The same vulnerability class exists in multiple widely used coding agents. DeepSeek-Reasonix is the first full disclosure. Others are under coordinated disclosure and will be published once fixes are available. GitLab found the same trust failure pattern earlier this year in Serena, another AI coding tool that ran attacker code from a project’s own .serena/project.yml file.
️ What to do
- Users: Update to DeepSeek-Reasonix Studio 2.21.0 or DeepSeek Reasonix npm 1.39.3. On older versions, do not diff any repository you did not clone directly yourself.
- Tool builders: Overriding four config keys is not enough. Override every relevant key on every git call, including
core.hooksPath,core.pager,core.editor,core.sshCommand,diff.external, and allfilter.*.cleanandfilter.*.smudgedrivers across.gitattributes,.git/info/attributes, and global or system attribute files. One flag does not cover another:--no-ext-diffaffectsdiff.externaland does nothing forcore.sshCommand. Alternatively, read blobs withgit cat-fileorgit showand diff in-process to avoid triggering the filter machinery altogether. - Security leads: Ask every vendor whose tool shells out to git how it neutralizes repository-local configuration. A tool running on a developer’s machine runs with that developer’s full access.
The fix shipped on 2026-09-30, the same day the advisory was published. The disclosure window opened on 2026-08-27.
