Mise Package Vulnerability: Arbitrary Code Execution via Tera Templates
An early warning has been issued regarding a potential vulnerability in the Mise package that could allow arbitrary code execution via Tera templates in.tool-versions files, affecting various versions.
What happened
Reportedly, the Mise package is vulnerable to arbitrary code execution through Tera templates in.tool-versions files. This vulnerability appears to enable attackers to bypass trust verification when Mise is operating in non-paranoid mode. The issue is under investigation with the tracked ID GHSA-FJJ5-V948-WHJJ. Affected versions include those introduced from '2026.3.15' to '2026.6.4', '2026.2.18' to '2026.6.4', '0' to '2026.6.4', '0' to '2026.6.1', and '0' to '2026.3.10'. It is recommended to avoid using .tool-versions files from untrusted repositories or to upgrade to a patched version if available. For more details, consult the primary sources.
How 0Day mitigates this
mise is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.