An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 15:17
Updated : 2026-09-11 17:35
NVD link : CVE-2026-87986
Mitre link : CVE-2026-87986
CVE.ORG link : CVE-2026-87986
JSON object : View
Products Affected
No product.
CWE
CWE-228
Improper Handling of Syntactically Invalid Structure
