Mistral AI Studio API files input filtering and access restriction
- Reference: MAI-2026-001
- Published: 2026-03-16
- Updated: 2026-03-16
- Severity: High
Mistral provides updates that help customers maintain the security of their on-premises systems. We strongly encourage on-premises customers to apply security patches.
Summary
Summary
A lack of filtering on the API /api/files can let a malicious user access unattended resources.
CVSS score
CVSS score
| Score | Severity | Version | Vector string |
|---|---|---|---|
| 7.0 | High | 3.1 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C |
CWE
CWE
- CWE-20: Improper input validation
Solution
Solution
| Software | Affected versions | Solution |
|---|---|---|
le-chat (docker ask/ui) | 1.75.12, except 1.75.12-hot4, to before 1.82.2 | Update to Mistral AI Studio 2026.1.3, 2026.2.0, or later. |
| Mistral AI Studio | 1.5.3-rc17 and later, 1.5.4, 1.5.5, 2026.1.0 | Update to Mistral AI Studio 2026.1.3, 2026.2.0, or later. |
| Mistral AI Studio | 2026.1.0, 2026.1.1, 2026.1.2 | Update to Mistral AI Studio 2026.1.3, 2026.2.0, or later. |
Note
Mistral changed its version numbering. Releases now use the format YYYY-MM-PATCHNUM, where YYYY is the release year, MM is the release month, and PATCHNUM is the patch version.