CVE-2026-35533 Details
Description
mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach dangerous directives such as [env] _.source, templates, hooks, or tasks.
A vulnerability exists in the 'mise' tool, which manages development utilities like Node.js, Python, CMake, and Terraform. Versions 2026.2.18 through 2026.4.5 are affected. The issue arises because 'mise' loads trust-control settings from a local project file, '.mise.toml', before verifying the file's trustworthiness. This flaw allows an attacker to place a malicious '.mise.toml' in a repository, making it appear trusted and enabling access to potentially harmful directives such as '[env] _.source', templates, hooks, or tasks.
Users are advised to remove or modify any 'trusted_config_paths' settings in local project configuration files to prevent this trust bypass. Additionally, 'mise' should be updated to a version where this vulnerability is addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jdx mise | >= 2026.2.18, <= 2026.4.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 7, 2026 | New CVE Received | [email protected] |