Mistral Vibe CLI MCP Configuration Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

Mistral Vibe trusts MCP configuration files within workspaces which can contain arbitrary commands that are executed upon load.

Timeline

Discovered on
December 11, 2025
Disclosed to Vendor on
December 11, 2025
Published on

Credit

Blog Post

References

Learn how Mindgard can help you navigate AI Security

Take the first step towards securing your AI. Book a demo now and we'll reach out to you.