Remote Code Execution Vulnerability in Mistral Vibe Software by Mistralai
CVE-2026-67623
8.6HIGH
What is CVE-2026-67623?
Mistral Vibe prior to version 2.23.3 is susceptible to a remote code execution vulnerability. This flaw enables malicious actors to execute arbitrary commands by embedding harmful core.fsmonitor hooks within a repository's .git/config file. When the vibe application runs the 'git status --porcelain' command without suppressing hook execution, these malicious hooks can be triggered, allowing the attacker to exploit the victim's privileges. Attackers can create or distribute a crafted repository containing this malicious fsmonitor entry, resulting in unauthorized command execution whenever a user runs vibe commands inside the affected repository.
Affected Version(s)
mistral-vibe 0
