OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102437

HIGH · CVSS 7.8 EPSS 0.99% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A local attacker with control over repository content in esengine DeepSeek-Reasonix can exploit an OS command injection vulnerability in the git diff filter mechanism to execute arbitrary commands through the desktop app's workspace-changes diff viewer. This high-severity flaw poses significant risks, particularly for organizations using this software for version control, as it could lead to unauthorized command execution and potential system compromise. Users and administrators of Reasonix Studio should prioritize immediate remediation to mitigate the threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102437
Severity
HIGH
CVSS
7.8
EPSS
0.99%

Original NVD Description

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.