Skip to main content
Disclosures

Mistral AI · Mistral Vibe

Workspace Permission Bypass via Shell Redirection

9.3critical
SecMateSECMATE-2026-0039
VendorMistral AI
ProductMistral Vibe
ClassificationDuplicate
VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Advisories
Timeline
Reported
Sep 5, 2026
Fixed
Sep 12, 2026
Published
Sep 18, 2026
Summary

Mistral Vibe versions 1.3.4 through 2.25.3 omit shell redirection targets from workspace permission checks. A command classified as safe can therefore read or write files outside the authorized workspace without the expected approval prompt, subject to the Vibe process's operating-system permissions and runtime controls. Repository-based exploitation requires Vibe to process attacker-controlled content and the model to emit a crafted shell tool call. SecMate independently reported this behavior to Mistral on September 5, 2026, before HiddenLayer published the overlapping CVE advisory on September 11. Version 2.25.4 fixes the issue.

Read the technical analysis

What's hidden in yours?

Find out