VYPR
Medium severity6.3NVD Advisory· Published Jun 26, 2026· Updated Jun 27, 2026

CVE-2026-55448

CVE-2026-55448

Description

mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decision, then executes that value with sh -c when resolving a GitHub token. An attacker who can place a .mise.toml in a repository can execute arbitrary shell commands when the victim runs a GitHub-related mise command and no higher-priority GitHub token environment variable is set. This vulnerability is fixed in 2026.6.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
misecrates.io
>= 2026.3.15, < 2026.6.42026.6.4

Affected products

1
  • Jdx/Misellm-fuzzy
    Range: >=2026.3.15 <2026.6.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.