Impact
An arbitrary code execution flaw in Mistral Vibe lets an attacker bypass command permission checks by leveraging shell constructs that the parser incorrectly ignores. The unparsed portions are dropped from inspection, allowing embedded commands to run on the system without approval, potentially giving full control over the affected host.
Affected Systems
The vulnerability affects Mistral Vibe from Mistralai. No specific version range is reported, so all deployed instances may be susceptible until a fix is issued.
Risk and Exploitability
The base CVSS score of 10 classifies this as Critical. While an EPSS score is not available and the flaw is not yet listed in CISA KEV, the flaw’s nature suggests that exploitation could occur through any input channel that reaches the vulnerable parser. Attackers could gain remote code execution if the vulnerable code executes commands in a system context, making the risk high for systems with exposed interfaces to the parser.
OpenCVE Enrichment