CVE-2026-87988
moderateArbitrary File Access via Workspace Bypass in Mistral Vibe
CVE-2026-87988 is an arbitrary file access vulnerability in Mistral AI's Vibe coding-agent product: commands that Vibe classifies as unconditionally allowed are executed without user approval, and those commands lack path validation. An attacker who can influence the commands the agent runs can therefore invoke one of these allow-listed commands with a path pointing outside the active workspace, bypassing the workspace restrictions that normally contain the agent. This yields unauthorized access to files outside the workspace without user consent, and the CVSS 4.0 base score of 10.0 (network vector, no privileges, no user interaction, high impact on all confidentiality, integrity, and availability components) indicates the isolation boundary can be defeated with full-scope impact. Any Mistral Vibe deployment that relies on workspace restrictions to contain the agent is affected; the available data does not specify affected or fixed version ranges. The flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation has not been confirmed.
What to do: No patched version number was provided in the available data, so monitor Mistral's official advisories and release notes and update Vibe as soon as a fixed release is published. Until then, review the set of commands Vibe treats as unconditionally allowed, constrain those commands to the workspace via least-privilege file permissions or OS-level isolation (e.g., container/chroot), and treat any untrusted input that can steer the agent's commands as a potential trigger for out-of-workspace file access.
| Mistral AI Mistral Vibe (agentic coding tool) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval.
- Weakness
- CWE-732
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.