Mistral Vibe 中存在一个任意文件写入漏洞,该漏洞首次出现在 1.3.4 版本中,使得攻击者能够在未经用户确认的情况下,在活动工作区之外创建或覆盖文件。由于 shell 重定向的目标路径未被包含在权限检查范围内,原本被允许的命令(即“允许列表”中的命令)得以将内容写入 Vibe 进程可访问的任意路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mistralai | mistral-vibe | 1.3.4 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87987 | 10.0 CRITICAL | Mistral Vibe:环境变量赋值绕过检查导致任意代码执行 |
| CVE-2026-87985 | 10.0 CRITICAL | Mistral Vibe 任意代码执行漏洞 |
| CVE-2026-87988 | 10.0 CRITICAL | Mistral Vibe 任意文件访问漏洞 |
| CVE-2026-87986 | 10.0 CRITICAL | Mistral Vibe 解析缺陷致任意代码执行漏洞 |
| CVE-2026-87983 | 9.2 CRITICAL | Mistral Vibe 2.6.0 任意文件读取漏洞 |
No comments yet