← Retour à la recherche de CVE

CVE-2026-67623

Description

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository-s .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim-s full privileges when any vibe command is run inside that repository.

CVSS 8.8EPSS 0.528%Risque 0.92
Voir la source
Publication
2026-08-05 14:17:10
Dernière modification
2026-08-06 13:18:22
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H