If you use Mistral’s AI coding agent, the Mistral Vibe vulnerability disclosed this week is worth stopping for. A flaw in how Vibe handles Git repositories let a booby-trapped project run code on your machine the moment you opened it as a worktree — no click, no download, just a folder. Mistral has already shipped a fix, but only if you actually update.
Quick facts if you’re short on time:
- Bug: CVE-2026-93993, a remote code execution flaw in Mistral Vibe’s Git worktree feature (CVSS 8.8)
- Published: September 19, 2026, a day after Mistral quietly shipped the fix
- Fixed in: Mistral Vibe version 2.25.5, released September 18
- Also patched: five earlier shell-permission bugs from version 2.25.4, one of them a maximum-severity CVSS 10
- What to do: run
vibe update, or reinstall via pip, npm, or the curl installer, right away
What the Mistral Vibe Vulnerability Actually Lets an Attacker Do
Vibe’s worktree feature lets you spin up an isolated coding session tied to a specific Git branch, which is handy when you’re juggling several tasks in one repo. The problem was in the order of operations. Vibe ran a repository’s Git hooks, including post-checkout, before it checked whether that repository was actually trusted.
That gap is exactly what CVE-2026-93993 exploits. An attacker packages a malicious post-checkout hook inside an otherwise normal-looking repository. The moment Vibe creates a worktree from it, the hook fires with whatever privileges your user account has, before any trust prompt appears.
You don’t need to run a suspicious command or approve anything for this to work. Cloning a repo, opening a pull request locally, or pointing Vibe at a shared project is enough. That’s what pushed the flaw to a CVSS score of 8.8.
Round One: Five Shell-Permission Bugs Fixed Last Week
This isn’t Mistral’s first patch cycle in September. On September 11 and 12, the team shipped version 2.25.4 to close five related bugs: CVE-2026-87984 through CVE-2026-87988. The worst of the batch, CVE-2026-87986, scored a perfect 10 out of 10 on CVSS.
The root cause was different from the worktree bug but just as blunt. Vibe’s permission system is supposed to flag risky shell commands and ask for approval before running them. The parser doing that checking couldn’t interpret certain shell constructs, so commands hidden inside them slipped straight past the workspace and denylist controls.
Version 2.25.4’s release notes describe the fix simply: shell permission checks now require approval for “risky syntax and command options that could bypass workspace and denylist controls.” In practice, that closes the exact kind of shortcut an attacker would use to smuggle commands past the guardrails.
How the Two Patch Rounds Compare
Here’s the pattern side by side, since the two fixes landed less than a week apart and get confused easily.
| Patch | CVEs | Bug type | Top severity |
|---|---|---|---|
| v2.25.4 (Sept 12) | CVE-2026-87984 to 87988 | Shell permission bypass | CVSS 10.0 |
| v2.25.5 (Sept 18) | CVE-2026-93993 | RCE via Git hooks in worktrees | CVSS 8.8 |
Both rounds trace back to the same underlying issue: Vibe needs real permission and shell access to be useful as a coding agent, and that power has to be gated correctly every single time. Mistral closed one gate in 2.25.4 and found another six days later.
Vibe isn’t alone here, either. AppAuxin covered a similar scare with the GitHub Copilot CLI vulnerability that could run malware on a developer’s machine. Terminal-based AI agents are a young category, and their security track record so far reflects that.
How to Update Mistral Vibe Right Now
Fixing this takes a couple of minutes. Open a terminal and run vibe update if you installed the CLI through Mistral’s own installer — it ships continuous updates for exactly this kind of situation.
If you installed Vibe through pip or npm instead, run pip install --upgrade mistral-vibe or npm update -g mistral-vibe, then check the version with vibe --version. You want to see 2.25.5 or later.
Until you’ve confirmed that, treat any repository you didn’t create yourself as untrusted. Don’t open it as a Vibe worktree, and don’t let the agent run checkout commands against it. The same caution applies to Vibe’s VS Code extension and desktop app, since both share the same worktree code path.
Coding agents keep expanding what they’re trusted to touch — Cognition’s coding agent Devin recently raised funding at a $48 billion valuation on the strength of that same autonomy. More access means more of exactly this kind of bug matters.
Frequently Asked Questions
Is Mistral Vibe safe to use now?
Yes, once you’re on version 2.25.5 or later. Both the worktree RCE bug and the earlier shell-permission bugs are patched in that release and everything after it.
What is Mistral Vibe, exactly?
It’s Mistral AI’s coding agent, available as a terminal CLI, a VS Code extension, and a web and desktop app. It can write code, run commands, and manage Git branches on your behalf.
How do I check what version of Mistral Vibe I’m running?
Type vibe --version in your terminal. If it shows anything earlier than 2.25.5, update immediately using the method you originally installed it with.
Was the Mistral Vibe vulnerability actually exploited?
No public proof-of-concept or confirmed attack had surfaced as of this vulnerability’s disclosure date. That’s good news, but it’s not a reason to delay updating.
Do I need to do anything if I only use the Mistral Vibe web app?
The worktree bug specifically affects the CLI, VS Code extension, and desktop app, which manage local Git repositories. The browser-only chat experience isn’t exposed to this particular flaw.
Here’s the honest read: a coding agent that can check out repositories and run shell commands is only as trustworthy as its permission checks, and Mistral has now had two of those checks fail in the same month. The fixes were fast and the company was transparent about both rounds, which counts for something. But if you’re running Vibe on a machine with anything sensitive on it, don’t wait for a reminder — update today, and treat every unfamiliar repository as guilty until proven innocent.


Leave a Reply