CVE Explorer
CVE-2026-54557
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the HTTP backend's symlink path uses the raw value. On Unix-like systems, if that version is an absolute path, PathBuf::join discards the intended mise installs root. A repository-controlled .tool-versions file can therefore mak
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mise","vendor":"jdx","versions":[{"status":"affected","version":"< 2026.6.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0f7fad10669ebae8c344ca1de93d10a39fbad0f90da952bc4ee19280b34b2ab9 · sha256:2059de10513576c8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0f7fad10669ebae8c344ca1de93d10a39fbad0f90da952bc4ee19280b34b2ab9 · sha256:2059de10513576c8… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0f7fad10669ebae8c344ca1de93d10a39fbad0f90da952bc4ee19280b34b2ab9 · sha256:2059de10513576c8… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/jdx/mise/security/advisories/GHSA-f94h-j2qg-fxw3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f7fad10669ebae8c344ca1de93d10a39fbad0f90da952bc4ee19280b34b2ab9 · sha256:2059de10513576c8… · /containers/adp/0/references/0
{"name":"https://github.com/jdx/mise/security/advisories/GHSA-f94h-j2qg-fxw3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/jdx/mise/security/advisories/GHSA-f94h-j2qg-fxw3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0f7fad10669ebae8c344ca1de93d10a39fbad0f90da952bc4ee19280b34b2ab9 · sha256:2059de10513576c8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.