Arbitrary File Access Vulnerability in Mistral Vibe by HiddenLayer
CVE-2026-87988

10CRITICAL

Key Information:

Vendor

Mistralai

Vendor
CVE Published:
11 September 2026

What is CVE-2026-87988?

An arbitrary file access vulnerability exists in Mistral Vibe, allowing attackers to bypass workspace restrictions using specific commands that are classified as unconditionally allowed. This flaw arises from inadequate path validation for these commands, resulting in unauthorized access to files located outside the designated workspace without the user's consent. Such vulnerabilities may expose sensitive data, posing risks to overall system security.

Affected Version(s)

mistral-vibe 2.15.0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.