CVE-2026-93993

8.8

Mistral AI · Mistral Vibe

Mistral Vibe before 2.25.5 is vulnerable to remote code execution during worktree creation because it executes git hooks before validating repository trust.

Executive summary

A remote code execution vulnerability in Mistral Vibe allows unauthenticated attackers to execute arbitrary shell commands by providing a malicious repository with a crafted post-checkout hook.

Vulnerability

This vulnerability, categorized as CWE-829, arises from the improper handling of git hooks during the worktree creation process. The application executes hooks from a supplied repository before performing necessary trust validation, allowing an unauthenticated attacker to achieve code execution with the privileges of the user running the Vibe process.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the host environment running Mistral Vibe. This facilitates unauthorized access to sensitive data, potential lateral movement within the network, and complete system compromise. Given the CVSS score of 8.8, this flaw represents a significant risk to organizational infrastructure and data integrity.

Remediation

Immediate Action: Update Mistral Vibe to version 2.25.5 or later immediately to incorporate the necessary trust validation logic during repository operations.

Proactive Monitoring: Review system and application logs for suspicious repository initialization events or unexpected shell process execution originating from the Vibe service account.

Compensating Controls: Restrict repository imports to trusted sources and implement strict egress filtering on servers running Mistral Vibe to prevent the application from interacting with untrusted or external Git repositories.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This is a high-severity vulnerability that poses a direct threat of remote code execution. Security teams must prioritize the update to version 2.25.5 across all environments. If an immediate update is not feasible, organizations should disable repository-related features until the patch can be applied to prevent potential exploitation.

More Mistral AI CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Mathieu Farrell, per the CVE Program record.