Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
An unauthenticated attacker over the network can execute arbitrary shell commands with the privileges of the user running Vibe by supplying a repository with a crafted post-checkout hook that is executed before trust validation.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Upgrade Mistral Vibe to version 2.25.5 or later. Until patching is possible, avoid cloning or creating worktrees from untrusted repositories.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-93993 . See article
NVD published the first details for CVE-2026-93993
A CVSS base score of 8.8 has been assigned.
GitHub Advisories released a security advisory .
Links to Mitre Att&cks
CVE-2026-93993 - Exploits & Severity - Feedly
CVE-2026-93993: Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout [HIGH] CVSS 8.6
CVE-2026-93993 - Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout CVE ID : CVE-2026-93993 Published : Sept. 19, 2026, 11:17 p.m. | 19 minutes ago Description : Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree...
CVE-2026-93993: Inclusion of Functionality from Untrusted Control Sphere in mistralai mistral-vibe
Be the first to know critical vulnerabilities
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
