CVE-2026-67623

HIGH

Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook

Title source: cna
STIX 2.1

Description

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.

References (7)

Core 7

Scores

CVSS v3 8.8
EPSS 0.0052
EPSS Percentile 41.1%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-829
Status published
Products (1)
mistralai/mistral-vibe < 2.23.3
Published Aug 05, 2026
Tracked Since Aug 05, 2026