CVE-2026-93993
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
- Published Sep 19, 2026
- CVSS 8.6 high
- 0.8% chance of exploitation in the next 30 days (EPSS)
- A fix is available