Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp
- Severity:
- Low
Description
Mistral npm @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp were compromised by a supply chain attack related to the TanStack security incident. An automated worm associated with the attack led to compromised npm package versions being published.
Recommendation
No fix is available yet. Followings are affected versions:
**= 1.7.3 = 1.7.2 = 1.7.1**
References
Related Issues
- Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai-azure - Vulnerability
- Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai - Vulnerability
- Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability - CVE-2024-35255
- Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability - @azure/identity - CVE-2024-35255
You might also like:
- Tags:
- npm
- @mistralai/mistralai-gcp
Anything's wrong? Let us know Last updated on May 18, 2026


