GHSA-8rx4-qgjw-3jvqHighCVSS 7.8

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.

🔗 References (4)