Mistral Vibe 中存在一个任意代码执行漏洞:攻击者可以通过在已允许的命令前插入环境变量赋值语句,从而绕过命令权限检查。由于这些赋值语句未被纳入检查范围,攻击者可以利用其控制的环境变量在未经用户确认的情况下触发任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mistralai | mistral-vibe | 2.6.0 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87985 | 10.0 CRITICAL | Mistral Vibe 任意代码执行漏洞 |
| CVE-2026-87988 | 10.0 CRITICAL | Mistral Vibe 任意文件访问漏洞 |
| CVE-2026-87986 | 10.0 CRITICAL | Mistral Vibe 解析缺陷致任意代码执行漏洞 |
| CVE-2026-87984 | 9.3 CRITICAL | Mistral Vibe 1.3.4 任意文件写入漏洞 |
| CVE-2026-87983 | 9.2 CRITICAL | Mistral Vibe 2.6.0 任意文件读取漏洞 |
No comments yet