Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
pkg:npm/
@earendil-works/pi-coding-agent
4 total CVEs
HIGH
1
MEDIUM
1
LOW
2
✅ Check your installed version
Check
All known vulnerabilities
HIGH
7.3
CVE-2026-54328
Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
>= 0.74.0, < 0.78.1
MEDIUM
4.4
CVE-2026-54325
Pi Agent: Pi loads project-local extensions without approval
from 0, < 0.79.0
LOW
2.5
CVE-2026-54326
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
>= 0.74.0, < 0.78.1
LOW
2.2
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
>= 0.74.0, < 0.78.1
CVE-2026-54327
npm/@earendil-works/pi-coding-agent — 4 CVEs · VulnScope