BlackTree Security · Infrastructure · Automation · AI

Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval

A Mistral Vibe permission bypass begins where a coding assistant is supposed to pause before a risky command. It asks for permission, and the developer decides whether the command may run. Six advisories published by HiddenLayer on 11 September 2026 show ways Mistral Vibe can make that decision using a different interpretation of the command from the one the shell ultimately executes.

That is a permission-boundary failure, not evidence of a mass intrusion. HiddenLayer published technical reproductions for six distinct flaws, with consequences ranging from reading files outside a project to arbitrary code execution as the user running Vibe. We found no confirmed malicious campaign exploiting these issues and no verified fixed-version mapping in the disclosed advisories as of 14 September. A CVSS 4.0 network vector in a record must not be read as proof that an unauthenticated attacker can send a packet to a public Vibe service. The demonstrated scenario depends on influencing a coding-agent command or its working context.

Six Mistral Vibe permission bypass routes around one decision

  • CVE-2026-87983, introduced in Vibe 2.6.0, uses quoted absolute paths. The approval check sees the quotes; the shell removes them. An allowlisted file-reading command can therefore access material outside the workspace without a prompt. HiddenLayer scores it 9.2.
  • CVE-2026-87984, introduced in 1.3.4, leaves shell redirection destinations out of the path check. A seemingly allowed command can write outside the workspace, with the process user’s permissions. It scores 9.3.
  • CVE-2026-87985, introduced in 2.9.0, uses ANSI-C shell quoting to conceal an argument from the parser. A command classed as safe may execute code when Bash restores the argument. It scores 10.0.
  • CVE-2026-87986, introduced in 1.3.4, concerns shell syntax that Vibe’s parser represents as an error or only partially understands. The real shell can still execute the hidden portion. It scores 10.0.
  • CVE-2026-87987, introduced in 2.6.0, ignores environment-variable prefixes in the approval decision. A program such as Git can behave differently under the supplied environment and run attacker-chosen code. It scores 10.0.
  • CVE-2026-87988, introduced in 2.15.0, expands the read-only command allowlist by 31 commands without applying equivalent path checks. Some utilities can read anywhere on the host; some also have output options that write files. It scores 10.0.

These Mistral Vibe permission bypass issues are separate, not six names for one proof of concept. The prerequisites and effects differ. The first two turn a workspace boundary into an unprompted read or write. The next three exploit gaps between Vibe’s command parser or approval representation and the operating system’s real execution. The last makes the label “read only” an unreliable proxy for a command’s actual filesystem effects.

Why the developer’s machine is the prize

Vibe runs with access to the user’s files and whatever credentials or tools the user made available. A working copy may be less sensitive than a cloud token, SSH key or configuration file elsewhere on the same host. If the agent can read or alter those files without the expected prompt, the developer’s mental model of containment is wrong.

An attacker does not need to own the workstation to make this interesting. A malicious repository, issue, documentation fragment or other untrusted text that the agent incorporates into its task could try to steer the agent into a crafted shell command. Whether a particular prompt-injection path succeeds depends on how Vibe is used and on the content the agent receives. HiddenLayer’s examples demonstrate the permission-check primitive; they do not prove every repository visit compromises a machine.

The practical review is to inventory where Vibe runs, which repositories and external instructions it reads, and what credentials are accessible to that process. Do not run an untrusted coding task with broad production secrets or administrator rights. A separate low-privilege account or container with restricted mounts can limit damage if the approval layer fails. Treat an auto-approved command as an execution decision, not a guarantee that the command is harmless. Review upstream releases and security guidance for an explicit fix that covers each of the six issues before concluding an update is sufficient.

The larger lesson is architectural. A permission dialog is only as sound as the code that decides when to show it. If validation sees a simplified command but Bash executes a richer one, the developer can never approve the action they did not get to see.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *