Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @earendil-works/pi-coding-agent
  4. ›
  5. CVE-2026-54327

CVE-2026-54327: Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

June 17, 2026

Exploitation requires local access to the same machine and read/traverse access to the victim’s Pi agent configuration directory. Users whose ~/.pi/agent directory is private to their account are less exposed. The main impact is disclosure of stored provider credentials, which may allow use of the configured provider accounts according to the privileges of those credentials.

This is not remotely exploitable by itself.

References

  • github.com/advisories/GHSA-r95r-rj6r-c39x
  • github.com/earendil-works/pi/commit/135fb545f99106a4a249274f129b90bc0a77d347
  • github.com/earendil-works/pi/releases/tag/v0.78.1
  • github.com/earendil-works/pi/security/advisories/GHSA-r95r-rj6r-c39x
  • nvd.nist.gov/vuln/detail/CVE-2026-54327

Code Behaviors & Features

Detect and mitigate CVE-2026-54327 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.74.0 before 0.78.1

Fixed versions

  • 0.78.1

Solution

Upgrade to version 0.78.1 or above.

Impact 2.2 LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
  • CWE-732: Incorrect Permission Assignment for Critical Resource

Source file

npm/@earendil-works/pi-coding-agent/CVE-2026-54327.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:22:31 +0000.