CVE-2026-87985

10.0

MistralAI · Mistral Vibe

Mistral Vibe contains an arbitrary code execution vulnerability involving improper inspection of ANSI-C quoted arguments, allowing unauthenticated attackers to bypass command permission checks.

Executive summary

An unauthenticated arbitrary code execution vulnerability in Mistral Vibe version 2.9.0 and later poses a critical risk to system integrity and confidentiality.

Vulnerability

The software fails to properly inspect ANSI-C quoted arguments, leading to an incomplete list of disallowed inputs (CWE-184). This allows an unauthenticated attacker to execute arbitrary code on the underlying system by crafting malicious commands that bypass existing permission checks.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code with the privileges of the application presents a total compromise scenario. This risk justifies the 10.0 CVSS score, as successful exploitation could lead to full system takeover, unauthorized access to sensitive data, and significant operational disruption.

Remediation

Immediate Action: As no specific patch version is currently identified, administrators should restrict network access to the affected instance and monitor vendor channels for the release of a security update.

Proactive Monitoring: Security teams should monitor system logs for unusual command execution patterns or unauthorized shell activity originating from the Mistral Vibe application.

Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect and filter incoming traffic for suspicious ANSI-C quoting sequences or unexpected command arguments.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical severity of this arbitrary code execution flaw and its potential for unauthenticated exploitation, immediate defensive measures are required. Organizations must prioritize isolating the affected systems from external networks and remain prepared to apply security patches immediately upon their release by the vendor.

More MistralAI CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources