{"id":"CVE-2026-54325","summary":"Pi loads project-local extensions without approval","details":"Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. This included project-local extensions, which are executable TypeScript or JavaScript modules loaded into the Pi process. An attacker who controls a repository could place Pi-specific project resources in that repository. If a user then started Pi from that working tree, the project-local extension code could run with the same privileges as the local Pi process without the user having a convenient way to make a trust decision. This vulnerability is fixed in 0.79.0.","aliases":["GHSA-mqxh-6gq7-558m"],"modified":"2026-08-12T03:51:35.682951614Z","published":"2026-06-23T19:22:55.043Z","database_specific":{"cwe_ids":["CWE-829"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54325.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/earendil-works/pi/releases/tag/v0.79.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54325.json"},{"type":"ADVISORY","url":"https://github.com/earendil-works/pi/security/advisories/GHSA-mqxh-6gq7-558m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54325"},{"type":"FIX","url":"https://github.com/earendil-works/pi/commit/38f18be44727e669eb0a6e2eb8edb51b0232d83c"},{"type":"FIX","url":"https://github.com/earendil-works/pi/commit/718215bd95b6fc6fa251580d27ea8aab857de390"},{"type":"FIX","url":"https://github.com/earendil-works/pi/commit/89a92207f1c9303d53d822fd9b0ac21578834cb4"},{"type":"FIX","url":"https://github.com/earendil-works/pi/commit/ce3a72444e1cc1eaa50475fb3378c7ffbb53ef49"},{"type":"FIX","url":"https://github.com/earendil-works/pi/commit/ff3e9df5f5b32368c20b0ef553a6834b3dee9350"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/earendil-works/pi","events":[{"introduced":"0"},{"fixed":"c10fb95fd993a1f6a92d5f770258fada1a20b55a"},{"fixed":"38f18be44727e669eb0a6e2eb8edb51b0232d83c"},{"fixed":"718215bd95b6fc6fa251580d27ea8aab857de390"},{"fixed":"89a92207f1c9303d53d822fd9b0ac21578834cb4"},{"fixed":"ce3a72444e1cc1eaa50475fb3378c7ffbb53ef49"},{"fixed":"ff3e9df5f5b32368c20b0ef553a6834b3dee9350"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.79.0"}]}}],"versions":["v0.78.1","v0.78.0","v0.77.0","v0.76.0","v0.75.5","v0.74.1","v0.75.4","v0.75.3","v0.75.2","v0.75.1","v0.75.0","v0.72.1","v0.72.0","v0.71.1","v0.71.0","v0.70.6","v0.70.5","v0.70.4","v0.70.3","v0.70.2","v0.70.1","v0.70.0","v0.69.0","v0.68.1","v0.68.0","v0.67.68","v0.67.67","v0.67.3","v0.67.2","v0.67.1","v0.67.0","v0.66.1","v0.66.0","v0.65.2","v0.65.1","v0.65.0","v0.64.0","v0.63.2","v0.63.1","v0.63.0","v0.62.0","v0.61.1","v0.61.0","v0.60.0","v0.59.0","v0.58.4","v0.58.3","v0.58.2","v0.58.1","v0.58.0","v0.57.1","v0.57.0","v0.56.3","v0.56.2","v0.56.1","v0.56.0","v0.55.4","v0.55.3","v0.55.2","v0.55.1","v0.55.0","v0.54.2","v0.54.1","v0.54.0","v0.53.1","v0.53.0","v0.52.12","v0.52.11","v0.52.10","v0.52.9","v0.52.8","v0.52.7","v0.52.6","v0.52.5","v0.52.4","v0.52.3","v0.52.2","v0.52.1","v0.52.0","v0.51.6","v0.51.5","v0.51.4","v0.51.3","v0.51.2","v0.51.1","v0.51.0","v0.50.9","v0.50.8","v0.50.7","v0.50.6","v0.50.5","v0.50.4","v0.50.3","v0.50.2","v0.50.1","v0.50.0","v0.49.3","v0.49.2","v0.49.1","v0.49.0","v0.48.0","v0.47.0","v0.46.0","v0.45.7","v0.45.6","v0.43.0","v0.42.5","v0.42.4","v0.42.3","v0.42.2","v0.42.1","v0.42.0","v0.41.0","v0.40.1","v0.40.0","v0.39.1","v0.39.0","v0.38.0","v0.37.8","v0.37.7","v0.37.6","v0.37.5","v0.37.4","v0.37.3","v0.37.2","v0.37.1","v0.37.0","v0.36.0","v0.34.2","v0.34.1","v0.34.0","v0.33.0","v0.32.3","v0.32.2","v0.32.1","v0.32.0","v0.30.2","v0.30.1","v0.30.0","v0.29.1","v0.29.0","v0.28.0","v0.27.9","v0.27.8","v0.27.7","v0.27.6","v0.27.5","v0.27.4","v0.27.3","v0.27.2","v0.27.1","v0.27.0","v0.26.1","v0.26.0","v0.25.4","v0.25.3","v0.25.2","v0.25.1","v0.25.0","v0.24.5","v0.24.4","v0.24.3","v0.24.2","v0.24.1","v0.24.0","v0.23.5","v0.23.4","v0.23.3","v0.23.2","v0.23.1","v0.23.0","v0.22.5","v0.22.4","v0.22.3","v0.22.2","v0.22.1","v0.22.0","v0.21.0","v0.20.2","v0.20.1","v0.20.0","v0.19.2","v0.19.1","v0.19.0","v0.18.8","v0.18.7","v0.18.6","v0.18.5","v0.18.4","v0.18.3","v0.18.2","v0.18.1","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.14.2","v0.14.1","v0.14.0","v0.13.2","v0.13.1","v0.13.0","v0.12.15","v0.12.14","v0.12.13","v0.12.12","v0.12.11","v0.12.10","v0.12.9","v0.12.8","v0.12.7","v0.12.5","v0.12.4","v0.12.3","v0.12.2","v0.12.1","v0.12.0","v0.11.6","v0.11.5","v0.11.4","v0.11.3","v0.11.2","v0.11.1","v0.11.0","v0.10.2","v0.10.1","v0.10.0","v0.9.4","v0.6.0","v0.0.2","v0.5.43","v0.5.35","v0.0.1","v0.5.7","v0.5.6","v0.5.5","v0.5.3-pods","v0.5.2","v0.5.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54325.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}