VYPR
Medium severity4.4GHSA Advisory· Published Jun 23, 2026· Updated Jun 25, 2026

CVE-2026-54325

CVE-2026-54325

Description

Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. This included project-local extensions, which are executable TypeScript or JavaScript modules loaded into the Pi process. An attacker who controls a repository could place Pi-specific project resources in that repository. If a user then started Pi from that working tree, the project-local extension code could run with the same privileges as the local Pi process without the user having a convenient way to make a trust decision. This vulnerability is fixed in 0.79.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@earendil-works/pi-coding-agentnpm
< 0.79.00.79.0

Affected products

1

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.