CVE-2026-87983
Mistral Vibe has a critical arbitrary file-read vulnerability introduced in version 2.6.0. Because quotation marks are not handled correctly during path validation, an attacker can use quoted absolute paths in allowlisted shell commands to bypass workspace restrictions and read files outside the active workspace without approval.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Mistral Vibe, with the vulnerability introduced in version 2.6.0. No affected products are listed in the CPE data.
Real-world impact
An attacker could read files that should be inaccessible from the active workspace.
Why this severity
CVSS base score: 9.2 (critical)
What to do about it
- ›Limit Mistral Vibe access to trusted users until a fix is available.
- ›Restrict allowlisted shell commands so untrusted users cannot submit quoted absolute paths that reach outside the active workspace.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No official fix is documented in the provided sources; the NVD description reports the issue, and CISA KEV lists no required action.