Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-87987: Mistral Vibe can run unwanted code via crafted commands
CVE-2026-87987 · published 29 days ago
Summary
The Mistral Vibe software can be tricked into executing code that an attacker supplies by using specially crafted command lines. This happens because the program does not check environment variable settings that appear before approved commands, allowing malicious code to run without user consent. Update the software to the latest version or apply the vendor’s patch to stop this behavior.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mistralai | mistral-vibe | <= * |
Original advisory text
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignm...
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
10.0
Critical
Type
CWE-15External Control of System or Configuration Setting
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta