
@secmatedev found two vulnerabilities in Mistral Vibe: arbitrary code execution and file access outside the workspace, both without the approval prompt users rely on. Full chain, from malicious repo to stolen Mistral token: https://blog.secmate.dev/posts/mistral-vibe-cve-2026-87987-cve-2026-87984/ https://t.co/Px5lAOqfR3
