VYPR
Vendor

Earendil Works

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2026-54328higJun 17, 2026
    risk 0.39cvss epss 0.00

    # Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a…

  • CVE-2026-54325Jun 17, 2026
    risk 0.00cvss epss 0.00

    # Pi loads project-local extensions without approval Pi before 0.79.0 loaded project-local configuration and resources from a repository's `.pi` directory without first asking the user to trust that repository. This included project-local extensions, which are executable…

  • CVE-2026-54327lowJun 17, 2026
    risk 0.00cvss epss 0.00

    # Pi auth.json writes could briefly expose stored credentials to local users Pi stored API keys and OAuth credentials in `auth.json`. A race condition in the file write path could briefly create or rewrite this file with permissions derived from the process umask before…

  • CVE-2026-54326lowJun 16, 2026
    risk 0.00cvss epss 0.00

    # Potential XSS in HTML session exports via Markdown URL handling Pi HTML exports render session Markdown into a static HTML file. Affected versions did not consistently reject unsafe Markdown link and image URL schemes. In versions with scheme filtering, C0 control characters…