Executive brief
Mistral Vibe is an AI coding assistant that enforces workspace restrictions to prevent access to sensitive files outside an active project directory. An attacker can bypass these restrictions by wrapping absolute file paths in shell quotes (e.g., cat "/etc/bashrc"), causing the security check to pass while the shell strips the quotes and executes the real path. This allows unauthorized reading of any file accessible to the Vibe process, including credentials, API tokens, SSH keys, and source code.
Technical details
This is a path traversal vulnerability (CWE-22) in Mistral Vibe's workspace restriction logic located in vibe/core/tools/builtins/bash.py. The vulnerable _extract_commands() function uses the raw text of parsed bash syntax nodes, including shell quotation marks, when reconstructing commands for the permission check. When is_path_within_workdir() evaluates a quoted path like "/etc/bashrc", it treats it as relative (since the first character is a quote, not a forward slash) and incorrectly determines it lies within the workspace. The allowlisted command (cat, head, tail, stat, wc) is approved without user interaction. However, the original bash command is executed with the quotation marks stripped by the shell, giving it access to the absolute path outside the workspace. The fix requires normalizing string nodes before path validation to work with effective shell arguments rather than raw tokens.
Affected products
- Mistral Vibe 2.6.0 and later
Timeline
- 2026-09-11: disclosed