CVE-2026-93993
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
19/09/2026
Last modified:
22/09/2026
Description
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/mistralai/mistral-vibe
- https://github.com/mistralai/mistral-vibe/blob/19b5b74faa78d0816b8d4d4c7d7543fc3520678c/vibe/core/git/repo.py#L411-L431
- https://github.com/mistralai/mistral-vibe/commit/c069ffa1e12fb5f2487b489217c40ab97721d553
- https://github.com/mistralai/mistral-vibe/issues/996
- https://github.com/mistralai/mistral-vibe/releases/tag/v2.25.5
- https://www.vulncheck.com/advisories/mistral-vibe-before-2.25.5-remote-code-execution-via-git-post-checkout
- https://github.com/mistralai/mistral-vibe/issues/996


