VYPR

Pi

by Earendil Works

Source repositories

CVEs (2)

  • CVE-2026-54325Jun 17, 2026
    risk 0.00cvss epss 0.00

    # Pi loads project-local extensions without approval Pi before 0.79.0 loaded project-local configuration and resources from a repository's `.pi` directory without first asking the user to trust that repository. This included project-local extensions, which are executable…

  • CVE-2026-54326lowJun 16, 2026
    risk 0.00cvss epss 0.00

    # Potential XSS in HTML session exports via Markdown URL handling Pi HTML exports render session Markdown into a static HTML file. Affected versions did not consistently reject unsafe Markdown link and image URL schemes. In versions with scheme filtering, C0 control characters…