---
id: CVE-2026-87987
title: >-
  An arbitrary code execution vulnerability in Mistral Vibe allows an attacker
  to bypass command permission checks using environment variable assignments
  preceding allowlisted commands
summary: >-
  An arbitrary code execution vulnerability in Mistral Vibe allows an attacker
  to bypass command permission checks using environment variable assignments
  preceding allowlisted commands. These assignments are excluded from
  inspection, enabl…
severity: critical
cvss: 10
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-15
vendor: mistralai
product: mistral-vibe
affected:
  - mistral-vibe >= 2.6.0 <= *
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87987'
references:
  - url: 'https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe5'
    label: 6f8de1f0-f67e-45a6-b68f-98777fdb759c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T14:59:24.182218Z'
cvssSource: cna
ingestedAt: '2026-09-11T16:45:47.862Z'
epss: 0.00564
epssPercentile: 0.44457
---

## Overview

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
