Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-87988: Mistral Vibe can let attackers read any file

CVE-2026-87988 · published 29 days ago
Summary

The Mistral Vibe application does not properly check file paths for certain commands, allowing a user to reach files outside the intended workspace. This could let an attacker view or modify data they should not access. Install the latest update or apply the vendor's recommended configuration changes to enforce proper path validation.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
mistralai mistral-vibe <= *
Original advisory text
An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these ...
An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-732Incorrect Permission Assignment for Critical Resource
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-87988 · MITRE
Track software like this
Free during beta