VYPR

Mistral Vibe

by Mistral

CVEs (3)

  • CVE-2026-87988CriSep 11, 2026
    risk 0.65cvss epss

    An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user…

  • CVE-2026-87986CriSep 11, 2026
    risk 0.65cvss epss

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without…

  • CVE-2026-87985CriSep 11, 2026
    risk 0.65cvss epss

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system…