Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35533

29
FAUCET Score

OVERVIEW CVE-2026-35533 affects mise, a popular developer tool manager for languages and utilities including Node, Python, CMake, and Terraform. Versions 2026.2.18 through 2026.4.5 contain a trust validation flaw where the application loads trust-control settings from a local project .mise.toml file before conducting security trust checks. This timing issue allows an attacker who gains repository access to inject a malicious .mise.toml configuration that bypasses trust verification and gains approval for execution. SEVERITY The vulnerability carries a HIGH CVSS score of 7.8, indicating significant risk. The attack requires local access and low privileges but is otherwise straightforward to execute, requiring no user interaction beyond normal tool operation. If exploited, the vulnerability grants an attacker the ability to execute arbitrary code through dangerous directives such as environment variable sourcing, template processing, hooks, and task execution, resulting in complete compromise of confidentiality, integrity, and availability on the affected system. EXPLOITATION STATUS The vulnerability demonstrates no current active exploitation, with no public exploit code confirmed available and minimal community attention to date. The extremely low EPSS score of 0.00005 indicates negligible real-world exploitation probability at this time. However, the moderate FAUCET risk score of 48.0 suggests the vulnerability warrants patching as part of standard maintenance, particularly in development environments where repository collaboration occurs.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2026.2.18, <= 2026.4.5CPE matchmatch criteria
cpe:2.3:a:jdx:mise:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
5.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 22nd percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

rustpatch availablevia ghsa
Product: miseFixed in: 2026.6.4
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

rustGHSA-436v-8fw5-4mj8high

Local settings bypass config trust checks

Apr 7, 2026

References

github.com / jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8
ExploitVendor Advisory