OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
{
"cna_assigner": "GitLab",
"cwe_ids": [
"CWE-78"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102437.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.21.0"
},
{
"fixed": "1.39.3"
}
],
"source": "AFFECTED_FIELD"
}