All 5 CVE vulnerabilities found in mise, with AI-generated Chinese analysis, references, and POCs.
Vendor: jdx
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-33646 | mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass) CWE-94 | 9.6 | Critical | 2026-06-26 |
| CVE-2026-55441 | mise: Arbitrary command execution via task-include files in an untrusted, config-less repository CWE-78 | 8.6 | High | 2026-06-26 |
| CVE-2026-54557 | mise HTTP backend uses raw version path for install symlink destination CWE-22 | 5.5 | Medium | 2026-06-26 |
| CVE-2026-55448 | mise: Local credential_command executes untrusted config CWE-78 | 6.3 | Medium | 2026-06-26 |
| CVE-2026-35533 | mise has a local settings bypass config trust checks CWE-284 | 7.8 | High | 2026-04-07 |
All 5 known CVE vulnerabilities affecting mise with full Chinese analysis, references, and POCs where available.