DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
GitLab's Threat Research Group discovered a command execution vulnerability (GHSA-grg2-7gc6-36m6, CVE-2026-102437) in DeepSeek-Reasonix Studio, a desktop git client designed for developers pairing with AI coding assistants. The flaw, called ConfigPoisoning, could allow attacker-supplied code to…
Sources
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| cvss high — 7.8 | 10 |