Junglewise Threat Intelligence

CVE-2026-54326: earendil-works Pi XSS in HTML session exports

CVE-2026-54326 · Severity: low · CVSS 3.1 · Published 2026-06-23

Technologies: Mariozechner Pi-Coding-Agent, @mariozechner/pi-coding-agent (npm), @earendil-works/pi-coding-agent (npm). Vendors: Earendil-Works, npm.

Executive brief

Pi, a terminal-based coding tool, is vulnerable to a security flaw when exporting coding sessions to HTML files. An attacker could potentially use malicious links to run unauthorized scripts if a user exports a session containing untrusted content and then opens that file in a web browser. This could lead to the limited exposure of data contained within that specific exported session file.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the HTML export functionality of the Pi coding harness. The root cause is improper neutralization of Markdown link and image URL schemes; specifically, C0 control characters could be used to bypass scheme filters because browsers normalize these characters before navigation. An exploit requires an attacker to inject malicious Markdown into a session (e.g., via prompt injection), followed by the user exporting the session to HTML and interacting with the malicious link. This results in script execution within the context of the static HTML document, potentially disclosing data embedded in that session file. The issue is fixed in version 0.78.1 by implementing an allow-list for schemes and stripping control characters.

Affected products

  • earendil-works pi-coding-agent >= 0.74.0, < 0.78.1
  • mariozechner pi-coding-agent >= 0.27.5, <= 0.73.1

Timeline

  • 2026-05-29: disclosed: Report received through GitHub Security Advisories
  • 2026-06-02: patched: Fix committed to repository
  • 2026-06-04: other: Fixed version 0.78.1 released
  • 2026-06-23: advisory: CVE published to NVD

References

Related threats