CVE-2026-102437
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
- CVSS
- 7.8
- EPSS
- 0.010 (61.2th percentile)
- CISA KEV
- Not listed
- Exploitation
- none
- Public exploits
- None seen
- State
- PUBLISHED
Coverage
GitLab BlogAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
GitLab's Threat Research Group discovered a command execution vulnerability (GHSA-grg2-7gc6-36m6, CVE-2026-102437) in DeepSeek-Reasonix Studio, a desktop git client designed for developers pairing with AI coding assistants. The flaw, called ConfigPoisoning, could allow attacker-supplied code to…
What we observed
No signals recorded