CARGO · JUNE 2026 · CONFIRMED

Mise Package Vulnerability: Arbitrary Code Execution via Tera Templates

GHSA-FJJ5-V948-WHJJghsa-fjj5-v948-whjjSeverity: HIGH

The Mise package has been confirmed to be vulnerable to arbitrary code execution via Tera templates in .tool-versions files, allowing attackers to execute commands without trust verification in non-paranoid mode.

What happened

According to the GitHub Security Advisory [GHSA-fjj5-v948-whjj], the Mise package is vulnerable to arbitrary code execution through Tera templates in.tool-versions files. This vulnerability allows attackers to execute commands without proper trust verification when operating in non-paranoid mode. To assess your exposure, check if your project utilizes Mise and incorporates.tool-versions files from untrusted sources.

The recommended action is to upgrade to the latest version of Mise and avoid using.tool-versions files from untrusted sources. For more detailed information and mitigation steps, consult the primary source [GHSA-fjj5-v948-whjj].

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If mise is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats