Junglewise Threat Intelligence

CVE-2026-87988: Mistral Vibe arbitrary file access via unvalidated read-only commands

CVE-2026-87988 · Severity: info · CVSS 10 · Published 2026-09-11

Technologies: Mistral Vibe. Vendors: Mistral.

Executive brief

Mistral Vibe is an AI coding assistant that runs commands within a controlled workspace to prevent unauthorized file access. A vulnerability in version 2.15.0 allows attackers to bypass these workspace restrictions by using 31 read-only utility commands (grep, find, diff, sort, etc.) to read sensitive files across the entire host system—including credentials, SSH keys, and source code—without user approval. Some commands can also write files, amplifying the risk.

Technical details

The vulnerability is a missing path validation flaw (CWE-732) in Mistral Vibe's command allowlisting logic. Version 2.15.0 added 37 POSIX utilities to _READ_ONLY_COMMANDS_POSIX but only 6 of them (cat, head, ls, stat, tail, wc) were also added to _PATH_COMMANDS, the list subject to workspace boundary checking. The remaining 31 commands (grep, diff, du, find, sort, uniq, less, md5sum, sha1sum, sha256sum, shasum, comm, join, paste, tac, and others) bypass _collect_outside_dirs() path validation entirely, allowing them to access absolute paths outside the workspace. No authentication or user interaction is required; an attacker with command execution in Vibe can invoke these utilities with arbitrary file paths. Some commands (sort with -o, uniq with output argument, less with output option) can also write files, extending exploitation beyond information disclosure.

Affected products

  • Mistral Vibe 2.15.0 and later

Timeline

  • 2026-09-11: disclosed

References

Related threats