oM noM Security Feeds cve
vulnerability context

CVE-2026-33646

CVSS 9.6 CRITICALCWE-94

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files, .tool-versions files are not subject to trust verification in non-paranoid mode. This means an attacker can place a malicious .tool-versions file in a git repository, and when a victim with mise activated cds into the directory, arbitrary commands execute without any trust prompt. This vulnerability is fixed in 2026.3.10.

Published 2026-06-26 · last modified 2026-06-26

details

CISA KEV status
Not in catalog
CVSS v3
9.6 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE
CWE-94
OTX pulses
0 total, 0 recent

source mentions 2

source consensus

  • Bluesky
  • GitHub Advisories
Want the 3-bullet summary of CVE-2026-33646, plus webhook alerts when KEV is updated? Pro is $10/mo.