Junglewise Threat Intelligence

CVE-2026-87987: Mistral Vibe environment variable injection in permission checks

CVE-2026-87987 · Severity: info · CVSS 10 · Published 2026-09-11

Executive brief

Mistral Vibe is an AI coding agent framework that automatically approves certain commands without user prompts. A flaw in its permission logic strips environment variable assignments before checking whether a command is allowlisted, enabling attackers to inject malicious environment variables (e.g., configuring Git to execute arbitrary programs) while the base command appears safe and auto-approved. This allows remote code execution without user consent.

Technical details

The vulnerability is an authorization bypass (CWE-15: External Control of System or Configuration Setting) in Mistral Vibe's command permission check logic. When a user (or AI agent) attempts to execute a shell command with environment variable prefixes (e.g., `VAR=value command`), the permission checker removes the environment assignments and only inspects the remaining command against an allowlist. If that allowlisted command exists in the default approval list (e.g., `git diff`), execution is auto-approved. However, Bash still launches the command with the full, original environment intact, allowing environment-controlled behavior in utilities like Git to trigger code execution—for example, `GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=diff.external GIT_CONFIG_VALUE_0='touch /tmp/pwned' git diff` auto-approves as `git diff` but executes the attacker-supplied diff program. Attack vector is network (via prompt injection in AI agents). No user interaction beyond the initial prompt is required. Patch availability has not been disclosed in the advisory.

Affected products

  • Mistral AI Vibe 2.6.0 and later

Timeline

  • 2026-09-11: disclosed: HiddenLayer SAI Security Advisory published

References