跳到正文
原文
about.gitlab.com· GitLab Threat Research Group(Abisheik Magesh, Daniel Abeles)·本站收录 · 原文发表 日期未知精选关注度44

GitLab 披露 DeepSeek-Reasonix Studio 配置投毒漏洞,可劫持 AI 编码 Agent

DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent

AI 导读

GitLab 威胁研究团队在 DeepSeek-Reasonix Studio 中发现命令执行漏洞 ConfigPoisoning(CVE-2026-102437),攻击者可通过仓库的 .git/config 与 .gitattributes 文件在开发者查看文件 diff 时执行任意代码。根因是 DeepSeek-Reasonix 的 git 封装加固了 core.fsmonitor、maintenance.auto 等键并加上 --no-ext-diff、--no-textconv,但未处理由 .gitattributes 按文件选择的 filter.<driver>.clean,该过滤器在生成 diff 比较 blob 时仍会运行,且每侧各触发一次。修复版本为 DeepSeek-Reasonix Studio 2.21.0 或 npm 1.39.3,影响桌面应用与 npm 包。

推荐理由

GitLab 威胁研究团队披露了编码 Agent 通过仓库配置执行任意命令的漏洞类别,并给出修复版本与通用加固建议。

阅读原文about.gitlab.com