CVE-2026-93993: Mistralai Mistral-Vibe
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
Affected products
- Mistralai Mistral-Vibe: before 2.25.5 (fixed in 2.25.5)
Published 2026-09-19. Last modified 2026-09-22.