CVE-2026-67623

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 14:17

Updated : 2026-08-06 13:18


NVD link : CVE-2026-67623

Mitre link : CVE-2026-67623

CVE.ORG link : CVE-2026-67623


JSON object : View

Products Affected

No product.

CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere