CVE detail
CVE-2026-67623
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repository containing a malicious fsmonitor entry to achieve arbitrary command execution with the victim's full privileges when any vibe command is run inside that repository.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 7
- within the 30d window
- Peak daily
- 7
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://therealcoiffeur.com/c111011.htmltherealcoiffeur.com
No excerpt available.
referencetherealcoiffeur.comAug 5, 2026, 2:17 PM - https://www.vulncheck.com/advisories/mistral-vibe-arbitrary-command-execution-via-git-fsmonitor-hookwww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comAug 5, 2026, 2:17 PM No excerpt available.
Exploitgithub.comAug 5, 2026, 2:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 2:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 2:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 2:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 2:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73073CVSS 7.1 · High
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficie…
- CVE-2026-73367CVSS 7.2 · High
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
- CVE-2026-73851CVSS 6.1 · Medium
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a f…
- CVE-2026-49986CVSS 7.1 · High
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically…
- CVE-2026-19884CVSS 8.4 · High
In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applica…
- CVE-2026-6464CVSS 8.1 · High
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN…