Arbitrary Code Execution Vulnerability in Mistral Vibe by HiddenLayer
CVE-2026-87987
10CRITICAL
What is CVE-2026-87987?
A vulnerability in Mistral Vibe allows attackers to execute arbitrary code by exploiting environment variable assignments. This security flaw allows command permission checks to be bypassed through intentionally crafted environment variables. The vulnerable implementation fails to inspect these variables, leading to unauthorized command execution without user consent, thereby posing a significant threat to the integrity of the system.
Affected Version(s)
mistral-vibe 2.6.0
