VulnSea

mistralai has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 10.0 (critical), with 6 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
10.0
Publish → KEV
Last 90 days
7 prev 0

Products

  • mistral-vibe 7
7
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

mistralai vulnerabilities

CVEs affecting mistralai, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-93993High· 8.8PoC
3d ago

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes…

Midnightmistralai · mistral-vibeEPSS 0.60%via NVD
CVE-2026-87983Critical· 9.2
1w ago

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during…

Midnightmistralai · mistral-vibeEPSS 0.42%via NVD
CVE-2026-87985Critical· 10.0
1w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute…

Midnightmistralai · mistral-vibeEPSS 0.44%via NVD
CVE-2026-87988Critical· 10.0
1w ago

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside…

Midnightmistralai · mistral-vibeEPSS 0.25%via NVD
CVE-2026-87987Critical· 10.0
1w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabl…

Midnightmistralai · mistral-vibeEPSS 0.33%via NVD
CVE-2026-87986Critical· 10.0
1w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded comman…

Midnightmistralai · mistral-vibeEPSS 0.44%via NVD
CVE-2026-87984Critical· 9.3
1w ago

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permi…

Midnightmistralai · mistral-vibeEPSS 0.43%via NVD
mistralai vulnerabilities (CVEs) · VulnSea