CVE-2026-87984: An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or over
highvulnerability
security
Summary
Mistral Vibe version 1.3.4 has a vulnerability that lets attackers write or overwrite files anywhere on the system without permission. The problem happens because shell redirection (using symbols like > to send output to files) isn't checked for permissions the same way regular commands are, so attackers can bypass security controls.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
September 11, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
integrityconfidentiality
AI Component TargetedFramework
Affected Vendors
Mistral
Related Issues
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-87984
First tracked: September 11, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 92%