CVE-2026-87988
An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- CWE
- CWE-732
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- mistralai mistral-vibe
Weakness type
Related vulnerabilities
- CVE-2026-57843 — NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information Disclosure
- CVE-2026-84828 — Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
- CVE-2026-19583 — Velociraptor Required Permissions bypass by using client monitoring queries
- CVE-2026-79617 — Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
- CVE-2026-80054 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-82312 — OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated...
- CVE-2026-80112 — PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys
- CVE-2021-43613 — SysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leading to escalation of privilege