SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-87987

CRITICAL · CVSS 10 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Mistral Vibe is vulnerable to an arbitrary code execution flaw that allows attackers to bypass command permission checks through manipulated environment variable assignments. This oversight enables the execution of arbitrary code without user consent, posing a critical risk to system integrity. Organizations using Mistral Vibe should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87987
Severity
CRITICAL
CVSS
10
EPSS
0.33%

Original NVD Description

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval.