Remote Code Execution Vulnerability in Mistral Vibe Software by Mistralai
CVE-2026-67623

8.6HIGH

Key Information:

Vendor

Mistralai

Vendor
CVE Published:
5 August 2026

What is CVE-2026-67623?

Mistral Vibe prior to version 2.23.3 is susceptible to a remote code execution vulnerability. This flaw enables malicious actors to execute arbitrary commands by embedding harmful core.fsmonitor hooks within a repository's .git/config file. When the vibe application runs the 'git status --porcelain' command without suppressing hook execution, these malicious hooks can be triggered, allowing the attacker to exploit the victim's privileges. Attackers can create or distribute a crafted repository containing this malicious fsmonitor entry, resulting in unauthorized command execution whenever a user runs vibe commands inside the affected repository.

Affected Version(s)

mistral-vibe 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mathieu Farrell
.