CVE-2026-93993

Summary

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.

Affected Software

VendorProductVersion RangeStatus
mistralaimistral-vibe0 < 2.25.5affected

Weaknesses

  • CWE-829: Inclusion of Functionality from Untrusted Control Sphere

References