Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-87984: Mistral Vibe could let attackers overwrite files

CVE-2026-87984 · published 29 days ago
Summary

Versions of Mistral Vibe starting with 1.3.4 allow a user to trick the program into creating or changing files outside the intended workspace. This happens because the software does not check where certain command outputs are sent, so an attacker could place or replace files that the program can access. Update to a version that fixes the check or apply the vendor's recommended patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
mistralai mistral-vibe <= *
Original advisory text
An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirec...
An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-87984 · MITRE
Track software like this
Free during beta