
Ryx@PadhiyarRushi
Mistral Vibe (CVE-2026-87988, CVSS 10.0) arbitrary file access via missing path validation on commands that were treated as unconditionally allowed. Unauthenticated attacker can break out of the intended workspace and read files they shouldn’t. Another case where “the command is allowed” was confused with “any path argument is safe.” https://cvebrief.com/cve/cve-2026-87988/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec
20041241
592 followersView on X
