Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m93j-546h-jwjv

Опубликовано: 11 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10

Описание

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval.

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval.

EPSS

Процентиль: 38%
0.00438
Низкий

10 Critical

CVSS4

Дефекты

CWE-228

Связанные уязвимости

nvd
13 дней назад

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval.

EPSS

Процентиль: 38%
0.00438
Низкий

10 Critical

CVSS4

Дефекты

CWE-228