Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-05 14:17
Updated : 2026-08-06 13:18
NVD link : CVE-2026-67623
Mitre link : CVE-2026-67623
CVE.ORG link : CVE-2026-67623
JSON object : View
Products Affected
No product.
CWE
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
