Mistral Vibe CLI Shell Expansion Command Execution

Affected Vendor(s)

Affected Product(s)

Summary

Shell expansion is not filtered when running commands, so it’s possible to run arbitrary OS commands through $() syntax.

Timeline

Discovered on
December 15, 2025
Disclosed to Vendor on
January 2, 2026
Published on

Credit

Blog Post

References

Learn how Mindgard can help you navigate AI Security

Take the first step towards securing your AI. Book a demo now and we'll reach out to you.