Mistral vulnerability
Published: Thu, 11 Jun 2026 12:55
Summary
Mistral could be made to expose sensitive information or run code.
Details
Eduardo Gonzalez Gutierrez and Arnaud Morin discovered that Mistral did not properly enforce access policies on some API endpoints. An attacker could possibly execute arbitrary code on a Mistral worker and possibly extract sensitive data including service credentials from it.
Recommended actions per Ubuntu release
StackPatch playbook auto-generated per release codename and per affected package.
Ubuntu jammy
mistral→14.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 14.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-api→14.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 14.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-api
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-common→14.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 14.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-common
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-engine→14.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 14.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-event-engine→14.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 14.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-event-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-executor→14.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 14.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-executor
Most apt upgrades restart their service automatically. needrestart lists anything else.
python3-mistral→14.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 14.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y python3-mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu noble
mistral→18.0.1-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 18.0.1-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-api→18.0.1-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 18.0.1-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-api
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-common→18.0.1-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 18.0.1-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-common
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-engine→18.0.1-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 18.0.1-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-event-engine→18.0.1-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 18.0.1-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-event-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-executor→18.0.1-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 18.0.1-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-executor
Most apt upgrades restart their service automatically. needrestart lists anything else.
python3-mistral→18.0.1-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 18.0.1-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y python3-mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu questing
mistral→21.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 21.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-api→21.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 21.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-api
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-common→21.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 21.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-common
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-engine→21.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 21.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-event-engine→21.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 21.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-event-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-executor→21.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 21.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-executor
Most apt upgrades restart their service automatically. needrestart lists anything else.
python3-mistral→21.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 21.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y python3-mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu resolute
mistral→22.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 22.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-api→22.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 22.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-api
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-common→22.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 22.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-common
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-engine→22.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 22.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-event-engine→22.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 22.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-event-engine
Most apt upgrades restart their service automatically. needrestart lists anything else.
mistral-executor→22.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 22.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y mistral-executor
Most apt upgrades restart their service automatically. needrestart lists anything else.
python3-mistral→22.0.0-0ubuntu1.1apt_upgradeStandard apt upgrade. Install 22.0.0-0ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y python3-mistral
Most apt upgrades restart their service automatically. needrestart lists anything else.
Are YOU affected by USN-8422-1?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8422-1 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
StackPatch runs this match against YOUR installed packages every hour
Free 1-server / $99 lifetime founder seat (50 only) / $19+/mo monthly. Indie pricing.