Arbitrary File Write Vulnerability in Mistral Vibe Software by HiddenLayer
CVE-2026-87984

9.3CRITICAL

Key Information:

Vendor

Mistralai

Vendor
CVE Published:
11 September 2026

What is CVE-2026-87984?

An arbitrary file write vulnerability in Mistral Vibe allows attackers to create or overwrite files beyond the active workspace without user consent. This issue arises due to a flaw in permission checks related to shell redirection destinations, which enables otherwise allowed commands to write to arbitrary locations accessible by the Vibe process. This can lead to significant security risks, enabling unauthorized access and manipulation of critical system files.

Affected Version(s)

mistral-vibe 1.3.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.