CVE-2026-71477
- EPSS 0.1%
- Veröffentlicht 18.08.2026 15:22:21
- Zuletzt bearbeitet 18.08.2026 16:18:16
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, al...
CVE-2026-33646
- EPSS 0.38%
- Veröffentlicht 26.06.2026 16:51:44
- Zuletzt bearbeitet 29.06.2026 14:16:49
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike...
CVE-2026-55441
- EPSS 0.13%
- Veröffentlicht 26.06.2026 16:48:23
- Zuletzt bearbeitet 26.06.2026 20:20:22
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but task-include files are loaded on a path that never reaches it. When a dire...
CVE-2026-54557
- EPSS 0.13%
- Veröffentlicht 26.06.2026 16:47:29
- Zuletzt bearbeitet 26.06.2026 20:20:22
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized ...
CVE-2026-55448
- EPSS 0.12%
- Veröffentlicht 26.06.2026 16:46:17
- Zuletzt bearbeitet 27.06.2026 04:17:51
mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decision, then executes that value with sh -c when resolving a GitHub token...
CVE-2026-35533
- EPSS 0.15%
- Veröffentlicht 07.04.2026 21:01:16
- Zuletzt bearbeitet 24.07.2026 21:10:00
mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repo...