← Zurück zur CVE-Suche

CVE-2026-67623

Beschreibung

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository-s .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim-s full privileges when any vibe command is run inside that repository.

CVSS 8.8EPSS 0.528%Risiko 0.92
Quelle öffnen
Veröffentlicht
2026-08-05 14:17:10
Zuletzt geändert
2026-08-06 13:18:22
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H