Security: jdx/mise
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Untrusted local .mise.toml [settings] can set the shell-interpreter args (default_inline/default_file shell_args), giving arbitrary command execution, because those interpreter settings were left off the global_only denylist added for CVE-2026-55448GHSA-g74g-rg72-j2p3 published
Jul 26, 2026 by jdxHigh -
Incorrect file ownership, when `mise` is installed by the root user using `install.sh`GHSA-9mm4-fgvc-x7rp published
Jul 7, 2026 by jdxModerate -
Arbitrary command execution via task-include files in an untrusted, config-less repositoryGHSA-77g9-363w-rccq published
Jun 12, 2026 by jdxHigh -
mise HTTP backend uses raw version path for install symlink destinationGHSA-f94h-j2qg-fxw3 published
Jun 12, 2026 by jdxModerate -
Local credential_command executes untrusted configGHSA-29hf-rm4x-xxph published
Jun 12, 2026 by jdxModerate -
Local settings bypass config trust checksGHSA-436v-8fw5-4mj8 published
Apr 3, 2026 by jdxHigh -
Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)GHSA-fjj5-v948-whjj published
Jun 12, 2026 by jdxCritical