@mariozechner/pi-coding-agent vulnerabilities
CVEs whose affected-version data names the @mariozechner/pi-coding-agent package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-54327Low· 2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
▾ Sunlitmariozechner · @mariozechner/pi-coding-agentEPSS 0.09%via GHSA
CVE-2026-54328High· 7.3Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
▾ Twilightearendil-works · @earendil-works/pi-coding-agentEPSS 0.16%via GHSA
CVE-2026-54326Low· 2.5Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
▾ Sunlitmariozechner · @mariozechner/pi-coding-agentEPSS 0.17%via GHSA