๐Ÿ” CVE Alert

CVE-2026-71477

MEDIUM 6.7

mise: Incorrect file ownership, when installed by the root user using `install.sh`

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, allowing a local user with those IDs to replace a root-installed executable, especially when MISE_INSTALL_PATH targets a shared location such as /usr/local/bin. This issue is fixed in version 2026.7.1.

CWE CWE-278
Vendor jdx
Product mise
Published Aug 18, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for jdx mise

Be the first to know when new medium vulnerabilities affecting jdx mise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

jdx / mise
< 2026.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jdx/mise/security/advisories/GHSA-9mm4-fgvc-x7rp github.com: https://github.com/jdx/mise/pull/10808 github.com: https://github.com/jdx/mise/pull/10819 github.com: https://github.com/jdx/mise/commit/b65dd674d75d9aa5c038b58a3a0cdb522cf258d5 github.com: https://github.com/jdx/mise/commit/f1c28906f17af74430ff96f4438733c4a842c88d github.com: https://github.com/jdx/mise/releases/tag/v2026.7.1