top of page
perceptive_background_267k.jpg

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmo…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 15:01:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Zero-Day Vulnerabilities, Supply Chain & Dependencies, Web Technologies

Mistral Vibe versions before 2.23.3 contain a remote code execution vulnerability exploitable via a malicious core.fsmonitor hook embedded in a repository's .git/config file. When a victim runs any vibe command inside a crafted repository, the tool invokes git status --porcelain without suppressing hook execution, triggering the malicious hook. This allows attackers to execute arbitrary commands with the victim's full privileges. The attack vector involves distributing or creating a specially crafted Git repository containing the malicious fsmonitor entry. The vulnerability is fixed in Mistral Vibe version 2.23.3, which suppresses hook execution when invoking git commands. Multiple GitHub references including the fix commit, issue tracker, and pull requests are available. The vulnerability has been assigned CVE-2026-67623 and is documented by VulnCheck as well.

Technical details

Mitigation steps:

Affected products:

Mistral Vibe

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page