SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-87988

CRITICAL · CVSS 10 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

An arbitrary file access vulnerability in Mistral Vibe allows attackers to bypass workspace restrictions, enabling unauthorized access to files outside the active workspace due to insufficient path validation. This critical flaw poses a significant risk of data exposure and should be prioritized by organizations using Mistral Vibe to safeguard sensitive information. Immediate remediation is essential to mitigate potential exploitation.

CVE
CVE-2026-87988
Severity
CRITICAL
CVSS
10
EPSS
0.25%

Original NVD Description

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval.