CVE-2026-54325

Source
https://cve.org/CVERecord?id=CVE-2026-54325
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54325.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54325
Aliases
Downstream
Published
2026-06-23T19:22:55Z
Modified
2026-08-12T03:51:35Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Pi loads project-local extensions without approval
Details

Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. This included project-local extensions, which are executable TypeScript or JavaScript modules loaded into the Pi process. An attacker who controls a repository could place Pi-specific project resources in that repository. If a user then started Pi from that working tree, the project-local extension code could run with the same privileges as the local Pi process without the user having a convenient way to make a trust decision. This vulnerability is fixed in 0.79.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-829"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54325.json"
}
References

Affected packages

Git / github.com/earendil-works/pi

Affected ranges

Type
GIT
Repo
https://github.com/earendil-works/pi
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.79.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.0.1
v0.0.2
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.11.6
v0.12.0
v0.12.1
v0.12.10
v0.12.11
v0.12.12
v0.12.13
v0.12.14
v0.12.15
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.7
v0.12.8
v0.12.9
v0.13.0
v0.13.1
v0.13.2
v0.14.0
v0.14.1
v0.14.2
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.18.1
v0.18.2
v0.18.3
v0.18.4
v0.18.5
v0.18.6
v0.18.7
v0.18.8
v0.19.0
v0.19.1
v0.19.2
v0.20.0
v0.20.1
v0.20.2
v0.21.0
v0.22.0
v0.22.1
v0.22.2
v0.22.3
v0.22.4
v0.22.5
v0.23.0
v0.23.1
v0.23.2
v0.23.3
v0.23.4
v0.23.5
v0.24.0
v0.24.1
v0.24.2
v0.24.3
v0.24.4
v0.24.5
v0.25.0
v0.25.1
v0.25.2
v0.25.3
v0.25.4
v0.26.0
v0.26.1
v0.27.0
v0.27.1
v0.27.2
v0.27.3
v0.27.4
v0.27.5
v0.27.6
v0.27.7
v0.27.8
v0.27.9
v0.28.0
v0.29.0
v0.29.1
v0.30.0
v0.30.1
v0.30.2
v0.32.0
v0.32.1
v0.32.2
v0.32.3
v0.33.0
v0.34.0
v0.34.1
v0.34.2
v0.36.0
v0.37.0
v0.37.1
v0.37.2
v0.37.3
v0.37.4
v0.37.5
v0.37.6
v0.37.7
v0.37.8
v0.38.0
v0.39.0
v0.39.1
v0.40.0
v0.40.1
v0.41.0
v0.42.0
v0.42.1
v0.42.2
v0.42.3
v0.42.4
v0.42.5
v0.43.0
v0.45.6
v0.45.7
v0.46.0
v0.47.0
v0.48.0
v0.49.0
v0.49.1
v0.49.2
v0.49.3
v0.5.1
v0.5.2
v0.5.3-pods
v0.5.35
v0.5.43
v0.5.5
v0.5.6
v0.5.7
v0.50.0
v0.50.1
v0.50.2
v0.50.3
v0.50.4
v0.50.5
v0.50.6
v0.50.7
v0.50.8
v0.50.9
v0.51.0
v0.51.1
v0.51.2
v0.51.3
v0.51.4
v0.51.5
v0.51.6
v0.52.0
v0.52.1
v0.52.10
v0.52.11
v0.52.12
v0.52.2
v0.52.3
v0.52.4
v0.52.5
v0.52.6
v0.52.7
v0.52.8
v0.52.9
v0.53.0
v0.53.1
v0.54.0
v0.54.1
v0.54.2
v0.55.0
v0.55.1
v0.55.2
v0.55.3
v0.55.4
v0.56.0
v0.56.1
v0.56.2
v0.56.3
v0.57.0
v0.57.1
v0.58.0
v0.58.1
v0.58.2
v0.58.3
v0.58.4
v0.59.0
v0.6.0
v0.60.0
v0.61.0
v0.61.1
v0.62.0
v0.63.0
v0.63.1
v0.63.2
v0.64.0
v0.65.0
v0.65.1
v0.65.2
v0.66.0
v0.66.1
v0.67.0
v0.67.1
v0.67.2
v0.67.3
v0.67.67
v0.67.68
v0.68.0
v0.68.1
v0.69.0
v0.70.0
v0.70.1
v0.70.2
v0.70.3
v0.70.4
v0.70.5
v0.70.6
v0.71.0
v0.71.1
v0.72.0
v0.72.1
v0.74.1
v0.75.0
v0.75.1
v0.75.2
v0.75.3
v0.75.4
v0.75.5
v0.76.0
v0.77.0
v0.78.0
v0.78.1
v0.9.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54325.json"