Remote Code Execution Vulnerability in Mistral Vibe Software by Mistralai
CVE-2026-67623
Key Information:
- Vendor
Mistralai
- Status
- Vendor
- CVE Published:
- 5 August 2026
Badges
What is CVE-2026-67623?
Mistral Vibe prior to version 2.23.3 is susceptible to a remote code execution vulnerability. This flaw enables malicious actors to execute arbitrary commands by embedding harmful core.fsmonitor hooks within a repository's .git/config file. When the vibe application runs the 'git status --porcelain' command without suppressing hook execution, these malicious hooks can be triggered, allowing the attacker to exploit the victim's privileges. Attackers can create or distribute a crafted repository containing this malicious fsmonitor entry, resulting in unauthorized command execution whenever a user runs vibe commands inside the affected repository.
Affected Version(s)
mistral-vibe 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
