Impact
An arbitrary file access vulnerability in Mistral Vibe allows attackers to bypass workspace restrictions by invoking commands that are categorized as unconditionally allowed. The missing path validation for these commands grants the ability to reference files outside the intended workspace without user approval, potentially exposing sensitive data or corrupting critical files. This flaw directly maps to improper permission checks and can enable a compromised user to read or modify protected files, threatening confidentiality and integrity.
Affected Systems
The affected product is Mistral Vibe from Mistralai. No specific version information was provided in the advisory, so the vulnerability may exist in any currently supported release of this product.
Risk and Exploitability
The CVSS base score is 10, indicating a critical impact. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack requires authenticated access to the service to issue the vulnerable commands, but the lack of path validation makes it exploitable once such access is gained.
OpenCVE Enrichment