CVE-2026-87985 Details
Description
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval.
A vulnerability in Mistral Vibe versions 2.9.0 and later allows arbitrary code execution by bypassing command permission checks with ANSI-C quoted arguments. These arguments are inadequately validated, enabling a crafted allowlisted command to execute arbitrary code on the user's system without authorization. The vulnerability arises because Vibe's command processing omits ANSI-C quoted strings, allowing dangerous predicates to be exploited without detection.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe3 | HiddenLayer | AdvisoryBundleTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-184 | Incomplete List of Disallowed Inputs | HiddenLayer |
Affected Products
| Product | Versions |
|---|---|
| Mistral Vibe | >= 2.9.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | New CVE Received | HiddenLayer |
| Sep 11, 2026 | CVE Modified | CISA-ADP |
Volerion