Arbitrary File Access Vulnerability in Mistral Vibe by HiddenLayer
CVE-2026-87988
10CRITICAL
What is CVE-2026-87988?
An arbitrary file access vulnerability exists in Mistral Vibe, allowing attackers to bypass workspace restrictions using specific commands that are classified as unconditionally allowed. This flaw arises from inadequate path validation for these commands, resulting in unauthorized access to files located outside the designated workspace without the user's consent. Such vulnerabilities may expose sensitive data, posing risks to overall system security.
Affected Version(s)
mistral-vibe 2.15.0
