CVE-2026-67623 HIGH

CVE-2026-67623: Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook

Vendor Mistralai
Product mistral-vibe
Weakness CWE-829 · Inclusion from untrusted sphere
Published August 5, 2026
Last update August 5, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.

Key dates

02Disclosure timeline

August 5, 2026 CVE published