CVE-2026-33646
- EPSS -
- Veröffentlicht 26.06.2026 16:51:44
- Zuletzt bearbeitet 26.06.2026 18:16:58
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike...
CVE-2026-55441
- EPSS -
- Veröffentlicht 26.06.2026 16:48:23
- Zuletzt bearbeitet 26.06.2026 18:17:01
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but task-include files are loaded on a path that never reaches it. When a dire...
CVE-2026-54557
- EPSS -
- Veröffentlicht 26.06.2026 16:47:29
- Zuletzt bearbeitet 26.06.2026 18:17:00
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized ...
CVE-2026-55448
- EPSS -
- Veröffentlicht 26.06.2026 16:46:17
- Zuletzt bearbeitet 26.06.2026 18:17:01
mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decision, then executes that value with sh -c when resolving a GitHub token...
CVE-2026-35533
- EPSS 0.15%
- Veröffentlicht 07.04.2026 21:01:16
- Zuletzt bearbeitet 15.04.2026 20:33:52
mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repo...