Home » Database

AVID-2026-R0436

Description

Mistral Vibe CLI MCP Configuration Code Execution

Details

Mistral Vibe trusts MCP configuration files within workspaces which can contain arbitrary commands that are executed upon load.

References

Affected or Relevant Artifacts

  • Developer: Mistral
  • Deployer:
  • Artifact Details:
TypeName
SystemVibe CLI

Impact

  • (none)

Other information

  • Report Type: Advisory
  • Credits: Piotr Ryciak, Mindgard
  • Date Reported: 2025-12-11
  • Version: 0.3.1
  • AVID Entry