Mistral Vibe 中存在一个任意代码执行漏洞。攻击者可以利用 shell 语法结构绕过命令权限检查,因为该工具的解析器无法解释这些结构。由于未被解析的部分会被忽略而不会受到检查,其中嵌入的命令便能在用户系统上未经批准即可执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mistralai | mistral-vibe | 1.3.4 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87987 | 10.0 CRITICAL | Mistral Vibe:环境变量赋值绕过检查导致任意代码执行 |
| CVE-2026-87985 | 10.0 CRITICAL | Mistral Vibe 任意代码执行漏洞 |
| CVE-2026-87988 | 10.0 CRITICAL | Mistral Vibe 任意文件访问漏洞 |
| CVE-2026-87984 | 9.3 CRITICAL | Mistral Vibe 1.3.4 任意文件写入漏洞 |
| CVE-2026-87983 | 9.2 CRITICAL | Mistral Vibe 2.6.0 任意文件读取漏洞 |
No comments yet