CVE-2026-54326

low

Description

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static HTML file. It did not consistently reject unsafe Markdown link and image URL schemes. In versions with scheme filtering, C0 control characters in the URL scheme could bypass the check because browsers normalize those characters before navigation. This vulnerability is fixed in 0.78.1.

References

https://github.com/earendil-works/pi/security/advisories/GHSA-7v5m-pr3q-6453

https://github.com/earendil-works/pi/releases/tag/v0.78.1

https://github.com/earendil-works/pi/commit/6cb23f9b5d5b6d1747672f535b167d0d809ac010

Details

Source: Mitre, NVD

Published: 2026-06-23

Updated: 2026-06-25

Risk Information

CVSS v2

Base Score: 1.2

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 2.5

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Severity: Low

EPSS

EPSS: 0.00018