
🤖🚨 VIEWING A GIT DIFF CAN TRIGGER ATTACKER CODE IN AN AI CODING AGENT GitLab Threat Research has disclosed a critical command-execution vulnerability affecting: DEEPSEEK-REASONIX CVE-2026-102437 aka "ConfigPoisoning" The trigger can be surprisingly mundane: A developer opens a FILE DIFF. The problem comes from how AI coding tools interact with Git. A malicious repository configuration can define a Git "clean" filter containing an attacker-controlled command. Then: * Developer opens a diff * Reasonix invokes Git * Git processes the configured filter * ATTACKER COMMAND EXECUTES GitLab reproduced the payload executing TWICE during a single diff operation. But the bigger finding is not Reasonix itself. GitLab says: "This is not an isolated DeepSeek-Reasonix bug." Researchers found MULTIPLE WIDELY USED CODING AGENTS susceptible to the same vulnerability class. Those products are currently under coordinated disclosure, and GitLab plans to reveal them after fixes become available. There's also an agentic-AI attack path. A compromised or PROMPT-INJECTED coding agent already running on a developer workstation could write the poisoned .git/config itself. That means an attacker may not need to distribute a specially packaged repository at all. ⚠️ Important limitation: A normal HTTPS/SSH Git clone does NOT transfer .git/config. Traditional delivery therefore requires mechanisms such as: * Repository archives * Synced folders * CI caches * Devcontainer builds But a local compromised AI agent can potentially create the malicious configuration directly. Patched versions: * DeepSeek-Reasonix Studio 2.21.0 * DeepSeek Reasonix npm 1.39.3 ⚠️ Analyst Note: AI coding agents increasingly execute trusted developer workflows with the developer's own privileges. That changes the security boundary. A repository is no longer merely CODE TO READ. Its configuration can become instructions consumed by an autonomous tool capable of executing commands on the workstation. And GitLab says more affected coding agents are coming. https://about.gitlab.com/blog/deepseek-reasonix-vulnerability-discovered/ #AISecurity #AIAgents #SupplyChain #Git #DeepSeek #CyberSecurity #ThreatIntel #DDW


