mise is vulnerable to Information Disclosure
59
Medium Risk
gitlab::get_headers and forgejo::get_headers attach the stored GitLab or Forgejo personal access token to any URL they are handed, without checking that the host matches the configured instance. The GitHub equivalent self-gates on is_github_api_url, but the GitLab and Forgejo paths carry no such check. A release asset link on an untrusted GitLab or Forgejo project can point at an attacker-controlled host, and a normal tool install then sends the bearer token to that host. The fix scopes both functions' token attachment to the configured instance host.
You are affected if you are using a version that falls within the vulnerable range and you use the GitLab or Forgejo backend with a configured personal access token.
mise is vulnerable to Information Disclosure in versions 0.0.1 - 2026.8.7.
Upgrade the mise library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.