• Sources: primary, discussion
  • Summary: SecMate reports that the Mistral Vibe permission layer evaluated a reduced parse of a shell command while the shell executed the original string. An allowlisted cat invocation therefore ran an attacker-selected binary with no approval prompt. SecMate covers five CVEs spanning versions 1.3.4 to 2.25.3 and instructs users to upgrade to 2.25.8.
  • Why it matters: A permission layer that reads a different command than the shell runs defeats allowlisting entirely, which is the control every agentic coding tool ships as its shell safeguard.
  • Follow-up: SecMate's report IDs and the published CVE scope do not map one to one, and SecMate states Mistral is still reconciling affected versions and CVSS with HiddenLayer. Track the final per-CVE scope.

send feedback on this story