CVE-2026-87985
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval.
| CWE | CWE-184 |
| Vendor | mistralai |
| Product | mistral-vibe |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for mistralai mistral-vibe
Be the first to know when new unknown vulnerabilities affecting mistralai mistral-vibe are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
mistralai / mistral-vibe
2.9.0 โค *