---
id: CVE-2026-87988
title: >-
  An arbitrary file access vulnerability in Mistral Vibe allows an attacker to
  bypass workspace restrictions through commands classified as unconditionally
  allowed
summary: >-
  An arbitrary file access vulnerability in Mistral Vibe allows an attacker to
  bypass workspace restrictions through commands classified as unconditionally
  allowed. Missing path validation for these commands enables access to files
  outside…
severity: critical
cvss: 10
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-732
vendor: mistralai
product: mistral-vibe
affected:
  - mistral-vibe >= 2.15.0 <= *
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87988'
references:
  - url: 'https://www.hiddenlayer.com/sai-security-advisory/2026-09-mistral-vibe6'
    label: 6f8de1f0-f67e-45a6-b68f-98777fdb759c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T15:00:15.022471Z'
cvssSource: cna
ingestedAt: '2026-09-11T16:45:47.862Z'
epss: 0.0043
epssPercentile: 0.34627
---

## Overview

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
