mise is vulnerable to OS Command Injection
78
High Risk
history.describe_command runs an arbitrary shell command whenever the bootstrap history watcher saves a checkpoint, passing the command JSON that includes a unified diff of the user's tracked dotfiles. Unlike the credential-command settings hardened for an earlier finding, history.describe_command is not marked global_only in settings.toml, so a project-local .mise.toml can set it. Routine commands such as mise install, mise exec, mise run, and mise watch implicitly trust the project directory with no explicit mise trust step or trust prompt, so the malicious command then runs and can exfiltrate credentials found in the tracked dotfiles. The fix marks history.describe_command global_only so local configs can no longer set it.
You are affected if you are using a version that falls within the vulnerable range and you use the bootstrap dotfiles history watcher.
mise is vulnerable to OS Command Injection in versions 2026.9.2 - 2026.9.6.
Upgrade the mise library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.