๐Ÿ” CVE Alert

CVE-2026-33646

CRITICAL 9.6

mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files, .tool-versions files are not subject to trust verification in non-paranoid mode. This means an attacker can place a malicious .tool-versions file in a git repository, and when a victim with mise activated cds into the directory, arbitrary commands execute without any trust prompt. This vulnerability is fixed in 2026.3.10.

CWE CWE-94
Vendor jdx
Product mise
Published Jun 26, 2026
Stay Ahead of the Next One

Get instant alerts for jdx mise

Be the first to know when new critical vulnerabilities affecting jdx mise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

jdx / mise
< 2026.3.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jdx/mise/security/advisories/GHSA-fjj5-v948-whjj