Description
An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

An arbitrary file write vulnerability has been discovered in Mistral Vibe, first appearing in version 1.3.4. The flaw allows an attacker to create or overwrite files outside the active workspace by bypassing permission checks on shell redirection destinations. This capability can enable modification of critical configuration files, execution of malicious code, or compromise of data integrity, thereby undermining both confidentiality and integrity of the system.

Affected Systems

The affected product is Mistralai’s Mistral Vibe, specifically version 1.3.4 and any builds that incorporate the vulnerable logic without correction. Users running this version in environments where the Vibe process has elevated privileges are at risk.

Risk and Exploitability

The vulnerability scores a high severe exploitation potential. EPSS data is not available, but the lack of mitigation makes the risk substantial. The issue is not listed in the CISA KEV catalog, yet a local attacker with access to the Vibe process can exploit the flaw, potentially leading to arbitrary code execution or data tampering.

Generated by OpenCVE AI on September 11, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Mistral Vibe that addresses the shell redirection flaw.
  • Disable or tightly restrict shell redirection features in the Vibe configuration to prevent unauthorized writes.
  • Monitor file system changes for unexpected writes outside the designated workspace and investigate quickly.

Generated by OpenCVE AI on September 11, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Arbitrary File Write via Shell Redirection in Mistral Vibe
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HiddenLayer

Published:

Updated: 2026-09-11T14:57:01.844Z

Reserved: 2026-09-09T19:14:18.451Z

Link: CVE-2026-87984

cve-icon Vulnrichment

Updated: 2026-09-11T14:55:06.961Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T15:17:07.383

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-87984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')