Arbitrary Code Execution Vulnerability in Mistral Vibe Software by HiddenLayer
CVE-2026-87985
10CRITICAL
What is CVE-2026-87985?
An arbitrary code execution vulnerability exists in Mistral Vibe, enabling attackers to bypass command permission checks through the manipulation of ANSI-C quoted arguments. Due to inadequate inspection of these arguments, a malicious user can craft a command that appears on the allowlist, leading to the execution of arbitrary code on a user's system without their consent. This flaw presents significant risks to users and necessitates immediate attention from all Mistral Vibe users to ensure system integrity.
Affected Version(s)
mistral-vibe 2.9.0
