OVERVIEW CVE-2026-35533 affects mise, a popular developer tool manager for languages and utilities including Node, Python, CMake, and Terraform. Versions 2026.2.18 through 2026.4.5 contain a trust validation flaw where the application loads trust-control settings from a local project .mise.toml file before conducting security trust checks. This timing issue allows an attacker who gains repository access to inject a malicious .mise.toml configuration that bypasses trust verification and gains approval for execution. SEVERITY The vulnerability carries a HIGH CVSS score of 7.8, indicating significant risk. The attack requires local access and low privileges but is otherwise straightforward to execute, requiring no user interaction beyond normal tool operation. If exploited, the vulnerability grants an attacker the ability to execute arbitrary code through dangerous directives such as environment variable sourcing, template processing, hooks, and task execution, resulting in complete compromise of confidentiality, integrity, and availability on the affected system. EXPLOITATION STATUS The vulnerability demonstrates no current active exploitation, with no public exploit code confirmed available and minimal community attention to date. The extremely low EPSS score of 0.00005 indicates negligible real-world exploitation probability at this time. However, the moderate FAUCET risk score of 48.0 suggests the vulnerability warrants patching as part of standard maintenance, particularly in development environments where repository collaboration occurs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2026.2.18, <= 2026.4.5CPE matchmatch criteria | cpe:2.3:a:jdx:mise:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.