{"apiVersion":"1.0","identifier":"CVE-2026-71477","description":"mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, allowing a local user with those IDs to replace a root-installed executable, especially when MISE_INSTALL_PATH targets a shared location such as /usr/local/bin. This issue is fixed in version 2026.7.1.","publishedAt":"2026-08-18T16:18:16","lastModifiedAt":"2026-08-18T16:18:16","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71477","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","epssProbability":0.00102,"riskScore":0.68,"affectedProduct":"mise","affectedVersions":"<2026.7.1","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-71477","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-71477","en":"https://www.redsauce.net/en/cves/CVE-2026-71477","fr":"https://www.redsauce.net/fr/cves/CVE-2026-71477","pt":"https://www.redsauce.net/pt/cves/CVE-2026-71477","de":"https://www.redsauce.net/de/cves/CVE-2026-71477","sk":"https://www.redsauce.net/sk/cves/CVE-2026-71477","el":"https://www.redsauce.net/el/cves/CVE-2026-71477"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-71477"}}