Back

HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in DeepSeek-Reasonix

Published Sep 29, 2026

Description

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.

Affected products

Remediation

Vendor solution

Upgrade Reasonix Studio to version 2.21.0 or above, or the reasonix npm package to version 1.39.3 or above.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Sep 29, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Awaiting Analysis
Modified Sep 29, 2026
Red Hat
Severity n/a
Public date n/a