CVE-2026-102437

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-10-03)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-10-02: 1Mentions · 2026-10-03: 210-0210-03
Referenced assets2 URLs
Full discourse3 posts
  • Dark Web Intelligence@DailyDarkWeb

    🤖🚨 VIEWING A GIT DIFF CAN TRIGGER ATTACKER CODE IN AN AI CODING AGENT GitLab Threat Research has disclosed a critical command-execution vulnerability affecting: DEEPSEEK-REASONIX CVE-2026-102437 aka "ConfigPoisoning" The trigger can be surprisingly mundane: A developer opens a FILE DIFF. The problem comes from how AI coding tools interact with Git. A malicious repository configuration can define a Git "clean" filter containing an attacker-controlled command. Then: * Developer opens a diff * Reasonix invokes Git * Git processes the configured filter * ATTACKER COMMAND EXECUTES GitLab reproduced the payload executing TWICE during a single diff operation. But the bigger finding is not Reasonix itself. GitLab says: "This is not an isolated DeepSeek-Reasonix bug." Researchers found MULTIPLE WIDELY USED CODING AGENTS susceptible to the same vulnerability class. Those products are currently under coordinated disclosure, and GitLab plans to reveal them after fixes become available. There's also an agentic-AI attack path. A compromised or PROMPT-INJECTED coding agent already running on a developer workstation could write the poisoned .git/config itself. That means an attacker may not need to distribute a specially packaged repository at all. ⚠️ Important limitation: A normal HTTPS/SSH Git clone does NOT transfer .git/config. Traditional delivery therefore requires mechanisms such as: * Repository archives * Synced folders * CI caches * Devcontainer builds But a local compromised AI agent can potentially create the malicious configuration directly. Patched versions: * DeepSeek-Reasonix Studio 2.21.0 * DeepSeek Reasonix npm 1.39.3 ⚠️ Analyst Note: AI coding agents increasingly execute trusted developer workflows with the developer's own privileges. That changes the security boundary. A repository is no longer merely CODE TO READ. Its configuration can become instructions consumed by an autonomous tool capable of executing commands on the workstation. And GitLab says more affected coding agents are coming. https://about.gitlab.com/blog/deepseek-reasonix-vulnerability-discovered/ #AISecurity #AIAgents #SupplyChain #Git #DeepSeek #CyberSecurity #ThreatIntel #DDW

    2101114.2K
    206.1K followersView on X
  • ExploitGrid@exploitgrid

    CVE-2026-102437 can execute attacker-controlled code when a developer views a file diff in DeepSeek-Reasonix. GitLab found coding agents exposed to the same vulnerability class. Fixed: Studio 2.21.0 / npm 1.39.3 #AISecurity #AIAgents #CyberSecurity https://exploitgrid.net/vulnerabilities/CVE-2026-102437

    0001037
    341 followersView on X
  • Chahat Sharma@Chahatusharma

    GitLab found a command execution flaw in DeepSeek-Reasonix Studio. Viewing a file's diff could run attacker code (CVE-2026-102437). The fix is Studio 2.21.0 or npm 1.39.3. GitLab says other coding agents share the same class of flaw. Which coding agents have you updated? https://t.co/NrfOePdW7s

    0000054
    658 followersView on X

Explore more