{"id":"CVE-2026-87987","title":"An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands","summary":"An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabl…","severity":"critical","cvss":10,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","cwe":["CWE-15"],"vendor":"mistralai","product":"mistral-vibe","affected":["mistral-vibe >= 2.6.0 <= *"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T17:35:21.440","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87987","references":[{"url":"https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe5","label":"6f8de1f0-f67e-45a6-b68f-98777fdb759c"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-11T14:59:24.182218Z"},"cvssSource":"cna","ingestedAt":"2026-09-11T16:45:47.862Z","epss":0.00333,"epssPercentile":0.26639,"slug":"CVE-2026-87987","body":"## Overview\n\nAn arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}