Impact
An arbitrary file write vulnerability has been discovered in Mistral Vibe, first appearing in version 1.3.4. The flaw allows an attacker to create or overwrite files outside the active workspace by bypassing permission checks on shell redirection destinations. This capability can enable modification of critical configuration files, execution of malicious code, or compromise of data integrity, thereby undermining both confidentiality and integrity of the system.
Affected Systems
The affected product is Mistralai’s Mistral Vibe, specifically version 1.3.4 and any builds that incorporate the vulnerable logic without correction. Users running this version in environments where the Vibe process has elevated privileges are at risk.
Risk and Exploitability
The vulnerability scores a high severe exploitation potential. EPSS data is not available, but the lack of mitigation makes the risk substantial. The issue is not listed in the CISA KEV catalog, yet a local attacker with access to the Vibe process can exploit the flaw, potentially leading to arbitrary code execution or data tampering.
OpenCVE Enrichment