Coding agent CLI with read, bash, edit, write tools and session management
@mariozechner/pi-coding-agent is deprecated — find an alternative
Update to >= 0.78.1 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| low | CVE-2026-54326 | Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass | 0.78.1 |
| high | CVE-2026-54328 | Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts | 0.78.1 |
| low | CVE-2026-54327 | Pi Agent: Race condition in Pi auth.json writes could expose stored credentials | 0.78.1 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/@mariozechner/pi-coding-agentFirst published · 2025-11-12T22:44:34.837Z
Last updated · 2026-05-07T14:45:19.966Z