rootpwn

critical · CVSS v3 8.8 · CVSS v4 8.6

CVE-2026-93993

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes…

Description

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.

Scores

Severity
critical
CVSS v2
10
CVSS v3
8.8
CVSS v4
8.6
EPSS

← All CVEs