Impact
An attacker can exploit Mistral Vibe by placing environment variable assignments before allowlisted commands. The system ignores these assignments during permission checks, allowing the attacker to inject arbitrary values that the application will execute as code. This flaw enables execution of code supplied by the attacker without user approval, compromising confidentiality, integrity, and availability of the affected system, which demonstrates a severe breach of trusted environments.
Affected Systems
The vulnerability affects the Mistral Vibe product from mistralai. No specific version information is listed, implying that all released versions of the product are potentially susceptible until patched by the vendor.
Risk and Exploitability
The CVSS score of 10 underscores the critical nature of this flaw. Although the EPSS score is unavailable, the lack of a KEV listing does not diminish the risk; the flaw remains unmitigated until addressed by the vendor. Based on the description, the likely attack vector is through any interface that permits environment variable assignment alongside command which could be exploitable remotely if the service is publicly exposed. The vulnerability can be leveraged by an attacker who can configure environment variables for privileged commands, leading to arbitrary code execution on the host.
OpenCVE Enrichment