CVE-2026-54326: low-severity vulnerability in earendil-works pi
Pi: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.5epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Markdown link and image URL schemes. In versions with scheme filtering, C0 control characters in the URL scheme could bypass the check because browsers normalize those characters before navigation. This vulnerability is fixed in 0.78.1.
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected products
earendil-works · piRelated CVEs — earendil-works pi
In the same product, most dangerous first.
CVE-2026-54325MEDIUMPi loads project-local extensions without approvalEPSS 0.2%CVE-2026-54328HIGHPi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hostsEPSS 0.2%CVE-2026-54327LOWPi: Race condition in auth.json writes could expose stored credentialsEPSS 0.1%