Mistral Vibe CLI MCP Configuration Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

Mistral Vibe trusts MCP configuration files within workspaces which can contain arbitrary commands that are executed upon load.

Timeline

Discovered on
December 11, 2025
Disclosed to Vendor on
December 11, 2025
Published on

Credit

Blog Post

References