Mistral Vibe 中存在任意文件访问漏洞:攻击者可以通过被归类为“无条件允许”的命令,绕过工作区限制。由于这些命令缺少路径验证机制,攻击者可以在未获用户批准的情况下,访问当前工作区之外的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mistralai | mistral-vibe | 2.15.0 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87987 | 10.0 CRITICAL | Mistral Vibe:环境变量赋值绕过检查导致任意代码执行 |
| CVE-2026-87985 | 10.0 CRITICAL | Mistral Vibe 任意代码执行漏洞 |
| CVE-2026-87986 | 10.0 CRITICAL | Mistral Vibe 解析缺陷致任意代码执行漏洞 |
| CVE-2026-87984 | 9.3 CRITICAL | Mistral Vibe 1.3.4 任意文件写入漏洞 |
| CVE-2026-87983 | 9.2 CRITICAL | Mistral Vibe 2.6.0 任意文件读取漏洞 |
No comments yet