Executive brief
A security vulnerability exists in the badlogic pi-mono web interface, specifically within its SVG artifact handling component. This flaw allows an attacker to perform cross-site scripting (XSS), which could lead to unauthorized actions being performed in a user's browser session. If a user views a specially crafted SVG file, the attacker could potentially steal session information or redirect the user to malicious websites.
Technical details
A cross-site scripting (XSS) vulnerability exists in badlogic pi-mono version 0.58.4. The issue is located in the SVG Artifact Handler component within the file 'packages/web-ui/src/tools/artifacts/SvgArtifact.ts'. The vulnerability stems from improper neutralization of input during web page generation (CWE-79), allowing for code injection (CWE-94). A remote attacker can exploit this by enticing a user to interact with a malicious SVG artifact. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. As of the advisory date, the vendor has not responded to disclosure attempts, and a proof-of-concept exploit is publicly available.
Affected products
- badlogic pi-mono 0.58.4
Timeline
- 2026-03-18: disclosed: Initial public disclosure via GitHub issue
- 2026-04-05: advisory: NVD publication date