CVE-2026-93993
8.8 HIGHpublic exploit availablePublished 2026-09-19 · Updated 2026-09-22
AI risk analysis
- Summary
- Mistral Vibe before 2.25.5 allows attackers to execute arbitrary shell commands by supplying a repository with a crafted post-checkout hook, leading to remote code execution.
- Exploitability
- Exploitation is relatively straightforward as attackers need only supply a repository with a malicious post-checkout hook. Precondition is access to the repository.
- Blast radius
- If exploited, the vulnerability could result in full compromise of the system running Vibe, potentially leading to data theft, service disruption, or further attacks.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Mistral Vibe 2.25.5 or later.
rcewebgitshell
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-829
Public exploit & PoC references
- https://github.com/mistralai/mistral-vibe
- https://github.com/mistralai/mistral-vibe/blob/19b5b74faa78d0816b8d4d4c7d7543fc3520678c/vibe/core/git/repo.py#L411-L431
- https://github.com/mistralai/mistral-vibe/commit/c069ffa1e12fb5f2487b489217c40ab97721d553
- https://github.com/mistralai/mistral-vibe/issues/996
- https://github.com/mistralai/mistral-vibe/releases/tag/v2.25.5
- https://github.com/mistralai/mistral-vibe/issues/996
All references
- https://github.com/mistralai/mistral-vibe
- https://github.com/mistralai/mistral-vibe/blob/19b5b74faa78d0816b8d4d4c7d7543fc3520678c/vibe/core/git/repo.py#L411-L431
- https://github.com/mistralai/mistral-vibe/commit/c069ffa1e12fb5f2487b489217c40ab97721d553
- https://github.com/mistralai/mistral-vibe/issues/996
- https://github.com/mistralai/mistral-vibe/releases/tag/v2.25.5
- https://www.vulncheck.com/advisories/mistral-vibe-before-2.25.5-remote-code-execution-via-git-post-checkout
- https://github.com/mistralai/mistral-vibe/issues/996
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-53988PoC
- CRITICALCVE-2026-84502
- HIGHCVE-2026-67623PoC
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- HIGHCVE-2025-1281
- CRITICALCVE-2025-29296
- HIGHCVE-2025-51457
Related by shared AI tags and CWE weakness class. Browse the full archive.