CVE-2026-87985
—Arbitrary Code Execution via ANSI-C Quoting Bypass in Mistral Vibe
Mistral Vibe contains an arbitrary code execution flaw in its command permission checking: arguments written as ANSI-C quoted strings are not inspected, so a command that appears allowlisted can carry hidden instructions past the approval check. An attacker who can influence the commands the agent runs (for example via untrusted content processed by the agent) can craft an allowlisted command that silently executes arbitrary code on the user's system without requiring user approval. Successful exploitation yields full compromise of the host running the agent, consistent with the maximum-impact CVSS 4.0 score of 10 (critical) across confidentiality, integrity, and availability. Users of Mistral Vibe who run the agent with a command allowlist, especially in automated or semi-automated workflows on untrusted input, are affected. No public proof of concept, in-the-wild exploitation, or KEV listing is currently known.
What to do: Check the installed Mistral Vibe version against the vendor's advisory and update to the patched release as soon as it is available. Until patched, tighten the command allowlist (remove broad entries that accept arbitrary arguments), avoid letting the agent act on untrusted content without supervision, and review command-approval logs for any allowlisted commands using ANSI-C quoting. Note that affected version ranges were not provided in this data, so verify coverage of your version before treating the issue as resolved.
| Mistral AI Mistral Vibe | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval.
- Weakness
- CWE-184
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.