Medium severity6.3NVD Advisory· Published Jun 26, 2026· Updated Jun 27, 2026
CVE-2026-55448
CVE-2026-55448
Description
mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decision, then executes that value with sh -c when resolving a GitHub token. An attacker who can place a .mise.toml in a repository can execute arbitrary shell commands when the victim runs a GitHub-related mise command and no higher-priority GitHub token environment variable is set. This vulnerability is fixed in 2026.6.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
misecrates.io | >= 2026.3.15, < 2026.6.4 | 2026.6.4 |
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.