Impact
Mistral Vibe prior to version 2.25.5 has a flaw in its worktree creation routine that runs Git hooks before validating trust. A maliciously crafted post‑checkout hook can be supplied as part of a repository; when the hook is executed it runs arbitrary shell commands with the privileges of the user that starts Vibe, enabling full remote code execution.
Affected Systems
The vulnerability affects the Mistral Vibe application distributed by mistralai under the product identifier "mistral‑vibe". All releases before v2.25.5 are impacted; the fix is included in the 2.25.5 release and later.
Risk and Exploitability
The CVSS score of 8.6 denotes high severity, and the missing EPSS value indicates no current estimate of exploitation frequency, but the potential is significant because the exploitation path requires only a crafted Git repository and does not rely on user interaction beyond the Vibe launch. The vulnerability is not listed in the CISA KEV catalog, but the impact remains that an attacker who can supply a malicious repository to the Vibe instance can execute arbitrary code with the instance’s user privileges.
OpenCVE Enrichment