CVE-2026-87984 Details
Description
An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.
An arbitrary file write vulnerability exists in Mistral Vibe versions 1.3.4 and later. This vulnerability allows an attacker to create or overwrite files outside the active workspace without user approval. The issue arises because shell redirection destinations are not subjected to permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process. As a result, this vulnerability could be exploited to modify source code or configuration, establish persistence, corrupt user data, or potentially achieve code execution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe2 | HiddenLayer | AdvisoryBundleExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | HiddenLayer |
Affected Products
| Product | Versions |
|---|---|
| Mistral Vibe | >= 1.3.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | New CVE Received | HiddenLayer |
| Sep 11, 2026 | CVE Modified | CISA-ADP |
Volerion