CVE-2026-87983 Details
Description
An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the active workspace to be read without user approval.
An arbitrary file read vulnerability exists in Mistral Vibe versions 2.6.0 and later. This vulnerability allows an attacker to bypass workspace restrictions by using quoted absolute paths in allowlisted shell commands. The issue arises from improper handling of quotation marks during path validation, enabling files outside the active workspace to be accessed without user consent. The vulnerability can expose any file accessible to the Vibe process, including sensitive information such as credentials, API tokens, SSH keys, configuration files, and source code.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe | HiddenLayer | AdvisoryBundleTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | HiddenLayer |
Affected Products
| Product | Versions |
|---|---|
| Mistral Vibe | >= 2.6.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | New CVE Received | HiddenLayer |
| Sep 11, 2026 | CVE Modified | CISA-ADP |
Volerion