<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:21:22 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-54328 — Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-54328</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; earendil-works pi&lt;/p&gt;
&lt;p&gt;Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extension package source. Pi could then load attacker-controlled extension code in the victim user&amp;#39;s process.  This vulnerability is fixed in 0.78.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; earendil-works pi&lt;/p&gt;
&lt;p&gt;Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extension package source. Pi could then load attacker-controlled extension code in the victim user&amp;#39;s process.  This vulnerability is fixed in 0.78.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-54328</guid>
    </item>
    <item>
      <title>GHSA-jfgx-wxx8-mp94 — Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jfgx-wxx8-mp94</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @earendil-works/pi-coding-agent, npm: @mariozechner/pi-coding-agent&lt;/p&gt;
&lt;p&gt;# Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts&lt;/p&gt;
&lt;p&gt;Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extension package source. Pi could then load attacker-controlled extension code in the victim user&amp;#39;s process.&lt;/p&gt;
&lt;p&gt;## Info&lt;/p&gt;
&lt;p&gt;The vulnerable code path affected temporary extension package sources loaded with `--extension` or `-e`, specifically npm and git package sources. The temporary npm install root and temporary git clone paths were deterministic and rooted under `os.tmpdir()/pi-extensions`. The path was derived from public source information rather than from a per-user private directory or an unpredictable temporary directory.&lt;/p&gt;
&lt;p&gt;During resource resolution, pi considered an npm package or git checkout present if the expected package path already existed. Extension resources discovered from that package location were then loaded by the extension loader. Because extensions execute with the same privileges as the invoking pi process, pre-created temporary package contents could execute as the victim user.&lt;/p&gt;
&lt;p&gt;The issue primarily affects Linux-based multi-user hosts where the operating system temporary directory is shared across user accounts, such as shared devel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @earendil-works/pi-coding-agent, npm: @mariozechner/pi-coding-agent&lt;/p&gt;
&lt;p&gt;# Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts&lt;/p&gt;
&lt;p&gt;Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extension package source. Pi could then load attacker-controlled extension code in the victim user&amp;#39;s process.&lt;/p&gt;
&lt;p&gt;## Info&lt;/p&gt;
&lt;p&gt;The vulnerable code path affected temporary extension package sources loaded with `--extension` or `-e`, specifically npm and git package sources. The temporary npm install root and temporary git clone paths were deterministic and rooted under `os.tmpdir()/pi-extensions`. The path was derived from public source information rather than from a per-user private directory or an unpredictable temporary directory.&lt;/p&gt;
&lt;p&gt;During resource resolution, pi considered an npm package or git checkout present if the expected package path already existed. Extension resources discovered from that package location were then loaded by the extension loader. Because extensions execute with the same privileges as the invoking pi process, pre-created temporary package contents could execute as the victim user.&lt;/p&gt;
&lt;p&gt;The issue primarily affects Linux-based multi-user hosts where the operating system temporary directory is shared across user accounts, such as shared devel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jfgx-wxx8-mp94</guid>
    </item>
  </channel>
</rss>
