# GitLab discloses DeepSeek-Reasonix flaw triggered by viewing diffs

_Published Friday, October 2, 2026 at 10:54 AM EDT · Security, AI · Latest · Tier 2 — Notable_

![GitLab discloses DeepSeek-Reasonix flaw triggered by viewing diffs — Primary](https://res.cloudinary.com/about-gitlab-com/image/upload/v1782237704/cj50chkvprjthczevmog.png)

GitLab disclosed a command-execution vulnerability in DeepSeek-Reasonix Studio that can run attacker code when a developer views a file's diff. Its researchers recommend updating to Studio 2.21.0 or DeepSeek Reasonix npm 1.39.3.

The flaw uses repository configuration to select a command that Git runs while preparing file content for comparison. Existing protections against external diff commands do not block this filter. Delivery requires a repository's local configuration through an archive, synced folder, CI cache or devcontainer build; ordinary HTTPS or SSH clones do not transfer it. A compromised coding agent with local filesystem access can also write the malicious configuration directly.

## Sources

- [GitLab](https://about.gitlab.com/blog/deepseek-reasonix-vulnerability-discovered/)

---
Canonical: https://techandbusiness.org/newswire/hw_OYoVR27dUaaPS3iZn3Y
Published: 2026-10-02T14:54:35.857Z
Story chronology: 2026-10-02T00:00:00.000Z
Retrieved: 2026-10-02T18:01:44.979Z
Publisher: Tech & Business (techandbusiness.org)
