Threat · curated 3 Oct 2026

Mistral Vibe Permission Bypass and Arbitrary Code Execution

Coverage timeline

23 Sep 2026secmate.dev

Single-source research — first reported, latest, and curated coincide.

Why it matters

Mistral Vibe's permission bypass shows how a mismatch between how an AI coding agent parses and executes shell commands lets attacker-controlled repository content achieve arbitrary code execution without user approval, a core risk for any auto-approving agentic tool.

SecMate disclosed two flaws in Mistral Vibe 2.25.0 (CVE-2026-87987 and CVE-2026-87984) where the coding agent's Bash tool used Tree-sitter to extract a reduced representation of a shell command for its permission allowlist, then executed the original untouched string. Hostile repository content could lead the model to emit a crafted tool call (e.g. an environment assignment prefixing an allowlisted command) that the permission parser classified as read-only, bypassing the approval prompt and enabling arbitrary code execution and reads/writes outside the authorized workspace. Mistral released Vibe 2.25.4 on September 12, 2026.