CVE-2026-67623
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
05/08/2026
Última modificación:
06/08/2026
Descripción
*** Pendiente de traducción *** Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.
Impacto
Puntuación base 4.0
8.60
Gravedad 4.0
ALTA
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/mistralai/mistral-vibe/commit/68ff32e6a92e80a874c8153312f0aa8ae4955477
- https://github.com/mistralai/mistral-vibe/issues/942
- https://github.com/mistralai/mistral-vibe/pull/962
- https://github.com/mistralai/mistral-vibe/pull/978
- https://github.com/mistralai/mistral-vibe/releases/tag/v2.23.3
- https://therealcoiffeur.com/c111011.html
- https://www.vulncheck.com/advisories/mistral-vibe-arbitrary-command-execution-via-git-fsmonitor-hook
- https://github.com/mistralai/mistral-vibe/issues/942


