Sceawere
Vulnerability Detail
CVE-2026-102437UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OS Command Injection in esengine
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 12h ago
- Vendor
- esengine
- Product
- DeepSeek-Reasonix
- Attack Type
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-29T13:17:50.493Z",
"pubdate": "2026-09-29T13:17:50.493Z",
"executiveSummary": "A critical OS Command Injection vulnerability exists within the esengine component of DeepSeek-Reasonix (Reasonix Studio).\nThe vulnerability resides in the internal/gitcmd module, specifically during the handling of git diff filter.clean and filter.smudge invocations.\nThis flaw allows a local attacker who has control over repository content, specifically .gitattributes and .git/config files, to execute arbitrary commands with the privileges of the desktop application.\nThe impact is significant, as it enables full code execution within the context of the workspace-changes diff viewer.\nExploitation requires the attacker to trick a user into viewing a malicious repository within the affected desktop application.\nThe risk is categorized as high due to the potential for unauthorized system access and local command execution.",
"technicalDetails": "The vulnerability is rooted in an insecure implementation of Git filter processes within the esengine module, specifically in internal/gitcmd.\nWhen the DeepSeek-Reasonix desktop application invokes a diff viewer for workspace changes, the underlying engine processes repository content. If the repository contains a maliciously crafted .gitattributes file in conjunction with a modified .git/config, the application inadvertently interprets these files to spawn external processes.\nIn Git, the 'filter' attribute allows for the definition of 'clean' and 'smudge' filters, which execute external scripts or binaries to process file contents. The vulnerability manifests because the application fails to adequately sanitize or restrict the execution environment when invoking these filters.\nThe attack flow begins when an attacker provides a compromised repository to a victim. The attacker configures the .gitattributes file to associate specific file types with a malicious filter defined in the .git/config file. When the victim opens the repository in the Reasonix Studio workspace-changes diff viewer, the application triggers a diff operation. During this operation, the engine attempts to resolve the configured filters.\nBecause the engine executes these filter commands without sufficient validation or path-based restrictions, it effectively executes the attacker-controlled strings as shell commands. This bypasses typical execution safeguards, allowing the payload to run with the security context and privileges of the desktop application process.\nSuccessful exploitation results in arbitrary OS command injection. The payload behavior is limited only by the permissions of the user running the application. Post-exploitation, an attacker could achieve persistence, exfiltrate sensitive local data, or pivot within the local environment, depending on the current user's system privileges."
}