Skip to main content
Disclosures

Mistral AI · Mistral Vibe

Shell Permission Bypass via Environment Assignments

10.0critical
SecMateSECMATE-2026-0038
VendorMistral AI
ProductMistral Vibe
ClassificationDuplicate
VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Advisories
Timeline
Reported
Sep 5, 2026
Fixed
Sep 12, 2026
Published
Sep 18, 2026
Summary

Mistral Vibe versions 2.6.0 through 2.25.3 omit environment assignments from shell permission checks while retaining them during execution. A command classified as safe can therefore execute an attacker-selected program without the expected approval prompt, with the permissions of the Vibe process. Repository-based exploitation requires Vibe to process attacker-controlled content and the model to emit a crafted shell tool call. SecMate independently reported this behavior to Mistral on September 5, 2026, before HiddenLayer published the overlapping CVE advisory on September 11. Version 2.25.4 fixes the issue.

Read the technical analysis

What's hidden in yours?

Find out