CVE-2026-67623 | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full pri
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.
- 🔗 therealcoiffeur.com/c111011.html
- 🔗 github.com/mistralai/mistral-vibe/issues/942
- 🔗 github.com/mistralai/mistral-vibe/releases/tag/v2.23…
- 🔗 github.com/mistralai/mistral-vibe/pull/962
- 🔗 github.com/mistralai/mistral-vibe/pull/978
- 🔗 github.com/mistralai/mistral-vibe/commit/68ff32e6a92…
- 🔗 www.vulncheck.com/advisories/mistral-vibe-arbitrary-command…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-15 | 2026-09-28 |
|---|---|---|
| ≥90 % | 0 | 299 |
| ≥50 % | 0 | 958 |
| ≥10 % | 0 | 3 |
| <10 % | 300 | 250 |
CVE-2026-67623 | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full pri
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invo
Noch keine Analyse zu CVE-2026-67623
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.