CVE-2026-87988: An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through comma
Summary
Mistral Vibe has a vulnerability where attackers can access files they shouldn't be able to reach by exploiting commands that skip safety checks (workspace restrictions, which limit what folders a user can access). The software doesn't properly validate file paths, meaning someone could read files outside their allowed workspace without permission.
Vulnerability Details
EPSS: 0.0%
September 11, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-87988
First tracked: September 11, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%