PT-2026-68171 · Unknown · Mistral-Vibe
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mistral Vibe versions prior to 2.23.3
Description
A remote code execution issue exists where attackers can execute arbitrary commands by embedding a malicious
core.fsmonitor hook within a repository's .git/config file. This is triggered when the software invokes the git status --porcelain command without suppressing hook execution. An attacker can distribute a crafted repository containing this malicious entry to execute commands with the victim's full privileges whenever any command is run inside that repository.Recommendations
Update Mistral Vibe to version 2.23.3 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mistral-Vibe