Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-93993: Mistral Vibe lets attackers run code remotely

CVE-2026-93993 · published 11 days ago
Summary

Versions of Mistral Vibe before 2.25.5 can run malicious commands when they process a specially crafted Git repository. An attacker could cause the software to execute any command with the same rights as the user running Vibe. Upgrade to version 2.25.5 or later to stop this behavior.

What to do
  • Update mistralai mistral-vibe to version 2.25.5 or later.
Affected software
VendorProductAffected versions
mistralai mistral-vibe < 2.25.5
Original advisory text
Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-829Inclusion of Functionality from Untrusted Control Sphere
Timeline
Published19 Sep 2026
Updated30 Sep 2026
First seen19 Sep 2026
Sources
CVE-2026-93993 · MITRE
Track software like this
Free during beta