PatchSiren

jdx CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM jdx CVE published 2026-08-18

CVE-2026-71477

CVE-2026-71477 debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T16:18:16.290Z and has not been modified since then. This medium-severity vulnerability in mise allows local users with specific IDs to replace root-installed executables, potentially leading to privilege escalation in shared environments. The issue is fixed in version 2026.7.1. System administrators and [truncated]

CRITICAL jdx CVE published 2026-06-26

CVE-2026-33646

CVE-2026-33646 is a critical vulnerability in mise, a development tool manager that handles various dev tools like node, python, cmake, and terraform. Prior to version 2026.3.10, mise is susceptible to arbitrary command execution due to its processing of .tool-versions files through the Tera template engine. The exec() function is registered during parsing, which enables an attacker to execute arbitrary c [truncated]

HIGH Jdx CVE published 2026-04-07

CVE-2026-35533

CVE-2026-35533 is a high-severity vulnerability in Mise, a tool for managing development tools like Node, Python, CMake, and Terraform. From version 2026.2.18 through 2026.4.5, Mise loads trust-control settings from a local project .mise.toml before the trust check runs. This allows an attacker who can place a malicious .mise.toml in a repository to make that same file appear trusted and then reach danger [truncated]