Unknown · Deepseek-Reasonix · CVE-2026-102437
**Name of the Vulnerable Software and Affected Versions**
DeepSeek-Reasonix Studio versions prior to 2.21.0
DeepSeek Reasonix npm versions prior to 1.39.3
**Description**
An OS command injection flaw exists in the `internal/gitcmd` component of DeepSeek-Reasonix (Reasonix Studio). A local attacker who controls repository content, specifically the `.gitattributes` and `.git/config` files, can execute arbitrary commands through the desktop application's workspace-changes diff viewer. The issue occurs because the tool fails to restrict the Git clean filter, allowing a malicious repository configuration to define a filter containing attacker-controlled commands that are executed when a developer opens a file diff.
Delivery of the malicious configuration typically requires mechanisms such as repository archives, synced folders, CI caches, or devcontainer builds, as standard HTTPS or SSH clones do not transfer the `.git/config` file. Additionally, a compromised or prompt-injected AI agent already running on a workstation could potentially write the poisoned configuration directly.
**Recommendations**
Update DeepSeek-Reasonix Studio to version 2.21.0.
Update DeepSeek Reasonix npm package to version 1.39.3.