@earendil-works/pi-coding-agent
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @earendil-works/pi-coding-agentpage 1 of 1
- CVE-2026-54325MEDIUMCVSS 4.4EG 4.4fixed in 0.79.02026-06-17
Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. This included project-local extensions, wh…
- CVE-2026-54326LOWCVSS 2.5EG 2.5fixed in 0.78.12026-06-16
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Markdown link and image URL schemes. In versions with scheme filterin…
- CVE-2026-54327LOWCVSS 2.2EG 2.2fixed in 0.78.12026-06-17
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could briefly create or rewrite this file with permissions derived from the p…
- CVE-2026-54328HIGHCVSS 7.3EG 7.3fixed in 0.78.12026-06-17
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a…
Check whether @earendil-works/pi-coding-agent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @earendil-works/pi-coding-agent CVEs against the assets you own.
Book a Demo →