Skip to content
CVE-2026-93993 - Exploits & Severity

CVE-2026-93993 - Exploits & Severity

Feedly September 20, 2026

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.

An unauthenticated attacker over the network can execute arbitrary shell commands with the privileges of the user running Vibe by supplying a repository with a crafted post-checkout hook that is executed before trust validation.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Upgrade Mistral Vibe to version 2.25.5 or later. Until patching is possible, avoid cloning or creating worktrees from untrusted repositories.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Feedly found the first article mentioning CVE-2026-93993 . See article

NVD published the first details for CVE-2026-93993

A CVSS base score of 8.8 has been assigned.

GitHub Advisories released a security advisory .

Links to Mitre Att&cks

CVE-2026-93993 - Exploits & Severity - Feedly

CVE-2026-93993: Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout [HIGH] CVSS 8.6

CVE-2026-93993 - Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout CVE ID : CVE-2026-93993 Published : Sept. 19, 2026, 11:17 p.m. | 19 minutes ago Description : Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree...

CVE-2026-93993: Inclusion of Functionality from Untrusted Control Sphere in mistralai mistral-vibe

Be the first to know critical vulnerabilities

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities