Mistral AI Studio API files input filtering and access restriction

  • Reference: MAI-2026-001
  • Published: 2026-03-16
  • Updated: 2026-03-16
  • Severity: High

Mistral provides updates that help customers maintain the security of their on-premises systems. We strongly encourage on-premises customers to apply security patches.

Summary

Summary

A lack of filtering on the API /api/files can let a malicious user access unattended resources.

CVSS score

CVSS score

ScoreSeverityVersionVector string
7.0High3.1AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C
CWE

CWE

  • CWE-20: Improper input validation
Solution

Solution

SoftwareAffected versionsSolution
le-chat (docker ask/ui)1.75.12, except 1.75.12-hot4, to before 1.82.2Update to Mistral AI Studio 2026.1.3, 2026.2.0, or later.
Mistral AI Studio1.5.3-rc17 and later, 1.5.4, 1.5.5, 2026.1.0Update to Mistral AI Studio 2026.1.3, 2026.2.0, or later.
Mistral AI Studio2026.1.0, 2026.1.1, 2026.1.2Update to Mistral AI Studio 2026.1.3, 2026.2.0, or later.
Note

Mistral changed its version numbering. Releases now use the format YYYY-MM-PATCHNUM, where YYYY is the release year, MM is the release month, and PATCHNUM is the patch version.