Vulnary
← back to the feed
Critical· 9.2

CVE-2026-87983

Mistral Vibe has a critical arbitrary file-read vulnerability introduced in version 2.6.0. Because quotation marks are not handled correctly during path validation, an attacker can use quoted absolute paths in allowlisted shell commands to bypass workspace restrictions and read files outside the active workspace without approval.

publishedSep 11, 2026
last modifiedSep 11, 2026
sourcesNVD
severity · cvss
9.2
critical · how bad it is
exploitation · epss
<1%
35th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 26, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Mistral Vibe, with the vulnerability introduced in version 2.6.0. No affected products are listed in the CPE data.

02

Real-world impact

An attacker could read files that should be inaccessible from the active workspace.

03

Why this severity

CVSS base score: 9.2 (critical)

04

What to do about it

no official fix yet
interim mitigations
  • Limit Mistral Vibe access to trusted users until a fix is available.
  • Restrict allowlisted shell commands so untrusted users cannot submit quoted absolute paths that reach outside the active workspace.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No official fix is documented in the provided sources; the NVD description reports the issue, and CISA KEV lists no required action.

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →