Mistral Vibe 2.25.5 之前的版本在 worktree 创建过程中存在一个远程代码执行(RCE)漏洞:该过程会在信任验证之前执行 Git 钩子(git hooks)。攻击者可以通过提供一个经过构造的 钩子,从而以运行 Vibe 的用户权限执行任意 Shell 命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mistralai | mistral-vibe | 0 ~ 2.25.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet