PatchSiren

Jdx CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL jdx CVE published 2026-06-26

CVE-2026-33646

CVE-2026-33646 is a critical vulnerability in mise, a development tool manager that handles various dev tools like node, python, cmake, and terraform. Prior to version 2026.3.10, mise is susceptible to arbitrary command execution due to its processing of .tool-versions files through the Tera template engine. The exec() function is registered during parsing, which enables an attacker to execute arbitrary c [truncated]

HIGH Jdx CVE published 2026-04-07

CVE-2026-35533

CVE-2026-35533 is a high-severity vulnerability in Mise, a tool for managing development tools like Node, Python, CMake, and Terraform. From version 2026.2.18 through 2026.4.5, Mise loads trust-control settings from a local project .mise.toml before the trust check runs. This allows an attacker who can place a malicious .mise.toml in a repository to make that same file appear trusted and then reach danger [truncated]