DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
GitLab's Threat Research Group finds a command-execution vulnerability in DeepSeek-Reasonix Studio, a desktop Git client for developers using AI coding assistants. The ConfigPoisoning flaw can run attacker-supplied code when a developer views a file diff; the supplied account identifies it as GHSA-grg2-7gc6-36m6 and CVE-2026-102437.
Developers using DeepSeek-Reasonix Studio face a code-execution risk triggered by viewing a diff, making this a direct software-supply-chain and endpoint security concern.