CVE-2026-54328
HIGH
7.3
CVSS 3.1
Description
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extension package source. Pi could then load attacker-controlled extension code in the victim user's process. This vulnerability is fixed in 0.78.1.
Metadata
Severity & Metrics
7.3
HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| earendil-works | pi | — | >= 0.74.0, < 0.78.1 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-379 | cna | CWE-379: Creation of Temporary File in Directory with Insecure Permissions |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.3 | HIGH | 3.1 | cna | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
References (5)
- https://github.com/earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94 https://github.com/earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94
- https://github.com/earendil-works/pi/pull/5345 https://github.com/earendil-works/pi/pull/5345
- https://github.com/earendil-works/pi/commit/a98e087e5d08ea2a536bf73dbb0aebb87c3ef72e https://github.com/earendil-works/pi/commit/a98e087e5d08ea2a536bf73dbb0aebb87c3ef72e
- https://github.com/earendil-works/pi/commit/ea3465a8e371a12d0167a06b60f93878e3a3df44 https://github.com/earendil-works/pi/commit/ea3465a8e371a12d0167a06b60f93878e3a3df44
- https://github.com/earendil-works/pi/releases/tag/v0.78.1 https://github.com/earendil-works/pi/releases/tag/v0.78.1