CVE-2026-102437: Esengine Deepseek-Reasonix

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.

Affected products

  • Esengine Deepseek-Reasonix: before 2.21.0 (fixed in 2.21.0); before 1.39.3 (fixed in 1.39.3)

Published 2026-09-29. Last modified 2026-09-29.