PatchSiren

mistralai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mistralai CVE published 2026-08-05

CVE-2026-67623

The CVE-2026-67623 vulnerability is a remote code execution vulnerability in Mistral Vibe before 2.23.3. This vulnerability allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. The vulnerability has a high impact on confidentiality, inte [truncated]