VYPR

Mistral.rs

by EricLBuehler

Source repositories

CVEs (1)

  • CVE-2026-108759MedOct 11, 2026
    risk 0.44cvss 6.8epss —

    mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers or prompt-injected agents can name symlinks as outputs or reuse sessions with…