Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-54328

25
FAUCET Score

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extension package source. Pi could then load attacker-controlled extension code in the victim user's process. This vulnerability is fixed in 0.78.1.

First published: Jun 23, 2026Last modified: Jun 23, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Earendil-WorksPi
>= 0.74.0, < 0.78.1CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 8th percentile among its peer group of 759 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: @earendil-works/pi-coding-agentFixed in: 0.78.1

Vendor Advisories (1)

npmGHSA-jfgx-wxx8-mp94high

Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts

Jun 17, 2026

References

github.com / earendil-works/pi/commit/a98e087e5d08ea2a536bf73dbb0aebb87c3ef72e
github.com / earendil-works/pi/commit/ea3465a8e371a12d0167a06b60f93878e3a3df44
github.com / earendil-works/pi/pull/5345
github.com / earendil-works/pi/releases/tag/v0.78.1
github.com / earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94