Junglewise Threat Intelligence

CVE-2026-5556: Badlogic pi-mono code injection in discoverAndLoadExtensions

CVE-2026-5556 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Technologies: Badlogic Pi-Mono. Vendors: Badlogic.

Executive brief

A security vulnerability has been identified in badlogic pi-mono, a coding agent component. An attacker could remotely inject and execute malicious code within the application. This could lead to unauthorized access to data, disruption of services, or full system compromise.

Technical details

A code injection vulnerability exists in the badlogic pi-mono library up to version 0.58.4. The flaw is located in the 'discoverAndLoadExtensions' function within 'packages/coding-agent/src/core/extensions/loader.ts'. By manipulating inputs to this function, a remote attacker with low privileges can achieve arbitrary code execution. The vulnerability is classified under CWE-94 (Improper Control of Generation of Code) and CWE-74 (Improper Neutralization of Special Elements). A public exploit has been disclosed, and as of the advisory date, the vendor has not provided a patch or response.

Affected products

  • badlogic pi-mono up to 0.58.4

Timeline

  • 2026-03-19: disclosed: Initial disclosure on GitHub issue tracker
  • 2026-04-05: advisory: NVD and VulDB publication date

References

Related threats