CVE-2026-87987

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 15:17

Updated : 2026-09-11 17:35


NVD link : CVE-2026-87987

Mitre link : CVE-2026-87987

CVE.ORG link : CVE-2026-87987


JSON object : View

Products Affected

No product.

CWE
CWE-15

External Control of System or Configuration Setting