Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-7059
  • npm/@cashback/how-it-works-widget
Malicious code in @cashback/how-it-works-widget (npm) 07 Jul
  • No fix available
GHSA-mqxh-6gq7-558m
  • npm/@earendil-works/pi-coding-agent
Pi Agent: Pi loads project-local extensions without approval 17 Jun
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-jfgx-wxx8-mp94
  • npm/@earendil-works/pi-coding-agent
  • npm/@mariozechner/pi-coding-agent
Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts 17 Jun
  • Fix available
  • Severity - 7.3 (High)
GHSA-r95r-rj6r-c39x
  • npm/@earendil-works/pi-coding-agent
  • npm/@mariozechner/pi-coding-agent
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials 17 Jun
  • Fix available
  • Severity - 2.2 (Low)
GHSA-7v5m-pr3q-6453
  • npm/@earendil-works/pi-coding-agent
  • npm/@mariozechner/pi-coding-agent
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass 16 Jun
  • Fix available
  • Severity - 2.5 (Low)
MAL-2025-35515
  • npm/test-mlw2-hided-works
Malicious code in test-mlw2-hided-works (npm) 14 Aug 2025
  • No fix available
MAL-2025-3893
  • npm/how-sezzle-works
Malicious code in how-sezzle-works (npm) 16 May 2025
  • No fix available
GHSA-vv7x-7w4m-q72f
  • npm/fhir-works-on-aws-authz-smart
fhir-works-on-aws-authz-smart handles permissions improperly 21 Sep 2022
  • Fix available
  • Severity - 6.5 (Medium)