Report security vulnerabilities in the Mistral CLI through the vulnerability disclosure section of https://mistral.ai/contact, which links to our reporting form. Reports are handled through our private disclosure program.
For other security questions, write to security@mistral.ai.
This policy covers the mistral CLI and its installer.
- A clear description of the vulnerability and its impact.
- The affected command or component, and the output of
mistral --version. - Steps to reproduce.
Redact credentials before you submit. API keys, tokens, and session cookies appear in shell history, config files, and stack traces. Remove them from any log output, terminal capture, or screenshot you attach.