Impact
An attacker can use quoted absolute paths in allowlisted shell commands to read any file on the system, bypassing workspace restrictions. This flaw allows the disclosure of sensitive data, excluding user authorization. The weakness corresponds to path traversal (CWE-22).
Affected Systems
Mistral Vibe 2.6.0 and subsequent builds that have not applied the vendor fix. The issue is present in all installations of the affected version regardless of deployment scenario.
Risk and Exploitability
The CVSS score of 9.2 reflects a severe confidentiality impact. The EPSS score is not available, making the exact exploitation probability hard to quantify; however, the lack of input sanitization makes this a straightforward local attack. The vulnerability is not listed in CISA’s KEV catalog. An attacker with local access to the workspace or compromised shell command, which is typical in many operational contexts, can readily exploit this flaw.
OpenCVE Enrichment