Vulnerabilities/

Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp - @mistralai/mistralai-azure

Severity:
Low

Description

Mistral npm @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp were compromised by a supply chain attack related to the TanStack security incident. An automated worm associated with the attack led to compromised npm package versions being published.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@mistralai/mistralai-azure
Anything's wrong? Let us know Last updated on May 18, 2026