HIGH
mise has a local settings bypass config trust checks
Published Apr 7, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach dangerous directives such as [env] _.source, templates, hooks, or tasks.
Affected products
-
Affected
- ≥ 2026.2.18, ≤ 2026.4.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19952 Advisory
- https://github.com/advisories/GHSA-436v-8fw5-4mj8 Advisory
- https://github.com/jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8 x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-35533
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19952 | Advisory | |
| https://github.com/advisories/GHSA-436v-8fw5-4mj8 | Advisory | |
| https://github.com/jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-35533 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 7, 2026
Updated Apr 8, 2026
Reserved Apr 3, 2026
Link CVE-2026-35533
CISA Vulnrichment
Updated Apr 8, 2026
Red Hat
No data
GitHub
Link GHSA-436V-8FW5-4MJ8