OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade Reasonix Studio to version 2.21.0 or above, or the reasonix npm package to version 1.39.3 or above.


Workaround

No workaround given by the vendor.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
Title Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in DeepSeek-Reasonix
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-29T13:25:35.445Z

Reserved: 2026-09-29T06:49:56.938Z

Link: CVE-2026-102437

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:50.493

Modified: 2026-09-29T13:17:50.493

Link: CVE-2026-102437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses