Mistral Vibe trusted a reduced representation of a shell command, then executed the original string. That gap turned commands classified as read-only into code execution without the expected approval prompt.

During a review of Mistral Vibe 2.25.0, SecMate found two related flaws:

  1. SECMATE-2026-0038: shell semantics omitted by the permission parser could execute arbitrary code.
  2. SECMATE-2026-0039: redirects, expansions, and option values could read or write outside the authorized workspace.

Repository-based delivery requires Vibe to process attacker-controlled content and the model to emit the crafted shell tool call. The permission bypass begins once that tool call reaches the Bash tool.

SecMate reported SECMATE-2026-0038 and SECMATE-2026-0039 to Mistral on September 5, 2026. HiddenLayer published its advisories on September 11, and Mistral released Vibe 2.25.4 on September 12. [1] [2]