CVE-2026-87986 Details
Description
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval.
An arbitrary code execution vulnerability exists in Mistral Vibe version 1.3.4. The issue arises because the application's command parser can misinterpret certain shell syntax, allowing attackers to embed executable commands within otherwise permissible ones. This exploitation bypasses the usual permission checks, enabling unauthorized command execution on the user's system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe4 | HiddenLayer | AdvisoryBundleTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-228 | Improper Handling of Syntactically Invalid Structure | HiddenLayer |
Affected Products
| Product | Versions |
|---|---|
| Mistral Vibe | >= 1.3.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | New CVE Received | HiddenLayer |
| Sep 11, 2026 | CVE Modified | CISA-ADP |
Volerion