cbcvebase.

Mistralai Mistral-Vibe vulnerabilities

8 known vulnerabilities affecting mistralai/mistral-vibe.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH2

Vulnerabilities

Page 1 of 1
CVE-2026-87985P2CRITICALCVSS 10.0≥ 2.9.0, ≤ *2026-09-11
CVE-2026-87985 [CRITICAL] CWE-184 CVE-2026-87985: An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permi An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval.
nvd
CVE-2026-87986P2CRITICALCVSS 10.0≥ 1.3.4, ≤ *2026-09-11
CVE-2026-87986 [CRITICAL] CWE-228 CVE-2026-87986: An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permi An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval.
nvd
CVE-2026-87988P2CRITICALCVSS 10.0≥ 2.15.0, ≤ *2026-09-11
CVE-2026-87988 [CRITICAL] CWE-732 CVE-2026-87988: An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restri An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval.
nvd
CVE-2026-87987P2CRITICALCVSS 10.0≥ 2.6.0, ≤ *2026-09-11
CVE-2026-87987 [CRITICAL] CWE-15 CVE-2026-87987: An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permi An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.
nvd
CVE-2026-87984P2CRITICALCVSS 9.3≥ 1.3.4, ≤ *2026-09-11
CVE-2026-87984 [CRITICAL] CWE-22 CVE-2026-87984: An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attack An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.
nvd
CVE-2026-93993P2HIGHCVSS 8.8fixed in 2.25.52026-09-19
CVE-2026-93993 [HIGH] CWE-829 CVE-2026-93993: Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation p Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
nvd
CVE-2026-87983P3CRITICALCVSS 9.2≥ 2.6.0, ≤ *2026-09-11
CVE-2026-87983 [CRITICAL] CWE-22 CVE-2026-87983: An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacke An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the active workspace to be read without user approval.
nvd
CVE-2026-67623P3HIGHCVSS 8.8fixed in 2.23.32026-08-05
CVE-2026-67623 [HIGH] CWE-829 CVE-2026-67623: Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to e Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can distribute or create a crafted repos
nvd
Mistralai Mistral-Vibe vulnerabilities | cvebase