事件观察中
DeepSeek-Reasonix 客户端 git 配置注入致命令执行漏洞
先了解这件事
AI 综述
2026年10月5日,GitLab 威胁研究团队披露 DeepSeek-Reasonix Studio 存在命令执行漏洞 ConfigPoisoning(CVE-2026-102437)。攻击者可通过仓库中的 .git/config 与 .gitattributes 文件,在开发者查看文件 diff 时执行任意代码。根因是 DeepSeek-Reasonix 的 git 封装虽加固了 core.fsmonitor、maintenance.auto 等键,但仍存在可被利用的配置注入路径。
AI 根据报道生成 · 2 天前更新
后续时间线
10月5日
- about.gitlab.com精选GitLab 披露 DeepSeek-Reasonix Studio 配置投毒漏洞,可劫持 AI 编码 Agent
GitLab 威胁研究团队在 DeepSeek-Reasonix Studio 中发现命令执行漏洞 ConfigPoisoning(CVE-2026-102437),攻击者可通过仓库的 .git/config 与 .gitattributes 文件在开发者查看文件 diff 时执行任意代码。根因是 DeepSeek-Reasonix 的 git 封装加固了 core.fsmonitor、maintenance.auto 等键并加上 --no-ext-diff、--no-textconv,但未处理由 .gitattributes 按文件选择的 filter.<driver>.clean,该过滤器在生成 diff 比较 blob 时仍会运行,且每侧各触发一次。修复版本为 DeepSeek-Reasonix Studio 2.21.0 或 npm 1.39.3,影响桌面应用与 npm 包。
相关讨论
关注度走势
每天新增来源
- 10月5日 新增 1 个来源(1 家媒体、0 个账号)
- 10月6日 新增 0 个来源(0 家媒体、0 个账号)
- 10月7日 新增 0 个来源(0 家媒体、0 个账号)