Mistral Vibe 中存在一个任意文件读取漏洞,该漏洞自 2.6.0 版本引入。攻击者可以利用允许列表中的 shell 命令使用带引号的绝对路径,从而绕过工作区限制。由于在路径验证过程中对引号的处理不当,使得攻击者能够在未经用户批准的情况下,读取当前活跃工作区之外的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mistralai | mistral-vibe | 2.6.0 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87987 | 10.0 CRITICAL | Mistral Vibe:环境变量赋值绕过检查导致任意代码执行 |
| CVE-2026-87985 | 10.0 CRITICAL | Mistral Vibe 任意代码执行漏洞 |
| CVE-2026-87988 | 10.0 CRITICAL | Mistral Vibe 任意文件访问漏洞 |
| CVE-2026-87986 | 10.0 CRITICAL | Mistral Vibe 解析缺陷致任意代码执行漏洞 |
| CVE-2026-87984 | 9.3 CRITICAL | Mistral Vibe 1.3.4 任意文件写入漏洞 |
No comments yet