CyberRota Analysis
AI-GeneratedA local attacker with control over repository content in esengine DeepSeek-Reasonix can exploit an OS command injection vulnerability in the git diff filter mechanism to execute arbitrary commands through the desktop app's workspace-changes diff viewer. This high-severity flaw poses significant risks, particularly for organizations using this software for version control, as it could lead to unauthorized command execution and potential system compromise. Users and administrators of Reasonix Studio should prioritize immediate remediation to mitigate the threat.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.