CVE-2026-67623
published 2026-08-05CVE-2026-67623: Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious…
PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.06%
63.2th percentile
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mistralai | mistral-vibe | < 2.23.3 | 2.23.3 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mistral AI Mistral Vibe up to 2.23.2 fsmonitor hook .git/config code injection
vuldb·2026-09-25·CVSS 8.8
CVE-2026-67623 [HIGH] Mistral AI Mistral Vibe up to 2.23.2 fsmonitor hook .git/config code injection
A vulnerability identified as critical has been detected in Mistral AI Mistral Vibe up to 2.23.2. The affected element is an unknown function of the file .git/config of the component fsmonitor hook. This manipulation causes code injection.
This vulnerability is tracked as CVE-2026-67623. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config
ghsa_unreviewed·2026-08-05
CVE-2026-67623 [HIGH] CWE-829 Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/mistralai/mistral-vibe/commit/68ff32e6a92e80a874c8153312f0aa8ae4955477https://github.com/mistralai/mistral-vibe/issues/942https://github.com/mistralai/mistral-vibe/pull/962https://github.com/mistralai/mistral-vibe/pull/978https://github.com/mistralai/mistral-vibe/releases/tag/v2.23.3https://therealcoiffeur.com/c111011.htmlhttps://www.vulncheck.com/advisories/mistral-vibe-arbitrary-command-execution-via-git-fsmonitor-hookhttps://github.com/mistralai/mistral-vibe/issues/942
2026-08-05
Published