Executive brief
Mistral Vibe is an AI-powered assistant for developers that can execute bash commands with workspace-based permission controls. A vulnerability in versions 1.3.4 and later allows attackers to create or overwrite files anywhere on the system by using shell redirects (e.g., `echo "pwned" > /tmp/pwned`) with allowlisted commands, bypassing workspace permission checks. An attacker could modify source code, corrupt configuration files, establish persistence, or achieve code execution with the privileges of the Vibe process.
Technical details
This is a path traversal vulnerability (CWE-22) where Mistral Vibe fails to validate shell redirection targets when performing permission checks. The vulnerability stems from the _extract_commands() function, which does not extract file_redirect nodes from the bash AST before reconstructing the command for permission checking. Allowlisted commands are approved for execution, but when a bash redirect is included in the original user input (e.g., `echo "pwned" > /tmp/pwned`), the redirect destination is never passed to _collect_outside_dirs() for validation. As a result, the permission check sees only the allowlisted command (`echo`) and grants approval automatically, while bash still receives and executes the full original input with the unvalidated redirect, allowing writes to arbitrary paths accessible to the Vibe process. No user approval is required, and the vulnerability is trivial to exploit—a simple redirect appended to any allowlisted command bypasses workspace protections. Patches should be available from Mistral AI.
Affected products
- Mistral Vibe 1.3.4 and later
Timeline
- 2026-09-11: disclosed
- 2026-09-11: advisory