Mise Package Vulnerability: Arbitrary Code Execution via Tera Templates
The Mise package has been confirmed to be vulnerable to arbitrary code execution via Tera templates in .tool-versions files, allowing attackers to execute commands without trust verification in non-paranoid mode.
What happened
According to the GitHub Security Advisory [GHSA-fjj5-v948-whjj], the Mise package is vulnerable to arbitrary code execution through Tera templates in.tool-versions files. This vulnerability allows attackers to execute commands without proper trust verification when operating in non-paranoid mode. To assess your exposure, check if your project utilizes Mise and incorporates.tool-versions files from untrusted sources.
The recommended action is to upgrade to the latest version of Mise and avoid using.tool-versions files from untrusted sources. For more detailed information and mitigation steps, consult the primary source [GHSA-fjj5-v948-whjj].
How 0Day mitigates this
mise is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.