PT-2026-77153 · Mise · Mise

CVE-2026-71477

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mise versions prior to 2026.7.1
Description Release tar archives record the mise/bin/mise file with user and group ID 1001. The packaging/standalone/install.envsubst function extracts and moves this file without normalizing ownership. This allows a local user possessing those specific IDs to replace a root-installed executable, particularly when the MISE INSTALL PATH variable targets a shared location such as /usr/local/bin.
Recommendations Update to version 2026.7.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71477
GHSA-9MM4-FGVC-X7RP

Affected Products

Mise