


Perceptive Security
SOC/SIEM Consultancy

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmo…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 15:01:49
Source:
nvd.nist.gov
Zero-Day Vulnerabilities, Supply Chain & Dependencies, Web Technologies
Mistral Vibe versions before 2.23.3 contain a remote code execution vulnerability exploitable via a malicious core.fsmonitor hook embedded in a repository's .git/config file. When a victim runs any vibe command inside a crafted repository, the tool invokes git status --porcelain without suppressing hook execution, triggering the malicious hook. This allows attackers to execute arbitrary commands with the victim's full privileges. The attack vector involves distributing or creating a specially crafted Git repository containing the malicious fsmonitor entry. The vulnerability is fixed in Mistral Vibe version 2.23.3, which suppresses hook execution when invoking git commands. Multiple GitHub references including the fix commit, issue tracker, and pull requests are available. The vulnerability has been assigned CVE-2026-67623 and is documented by VulnCheck as well.
Technical details
Mitigation steps:
Affected products:
Mistral Vibe
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67623
https://github.com/mistralai/mistral-vibe/commit/68ff32e6a92e80a874c8153312f0aa8ae4955477
https://github.com/mistralai/mistral-vibe/issues/942
https://github.com/mistralai/mistral-vibe/pull/962
https://github.com/mistralai/mistral-vibe/pull/978
https://github.com/mistralai/mistral-vibe/releases/tag/v2.23.3
https://www.vulncheck.com/advisories/mistral-vibe-arbitrary-command-execution-via-git-fsmonitor-hook
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
