---
id: CVE-2026-87984
title: >-
  An arbitrary file write vulnerability in Mistral Vibe, introduced in version
  1.3.4, allows an attacker to create or overwrite files outside the active
  workspace without user approval
summary: >-
  An arbitrary file write vulnerability in Mistral Vibe, introduced in version
  1.3.4, allows an attacker to create or overwrite files outside the active
  workspace without user approval. Shell redirection destinations are omitted
  from permi…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-22
vendor: mistralai
product: mistral-vibe
affected:
  - mistral-vibe >= 1.3.4 <= *
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87984'
references:
  - url: 'https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe2'
    label: 6f8de1f0-f67e-45a6-b68f-98777fdb759c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T14:54:22.701507Z'
cvssSource: cna
ingestedAt: '2026-09-11T16:45:47.862Z'
epss: 0.00496
epssPercentile: 0.39894
---

## Overview

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
