Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r95r-rj6r-c39x | Pi Agent: Race condition in Pi auth.json writes could expose stored credentials |
Fri, 26 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Earendil-works
Earendil-works pi |
|
| Vendors & Products |
Earendil-works
Earendil-works pi |
Tue, 23 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could briefly create or rewrite this file with permissions derived from the process umask before tightening the file to owner-only permissions. This vulnerability is fixed in 0.78.1. | |
| Title | Pi: Race condition in auth.json writes could expose stored credentials | |
| Weaknesses | CWE-367 CWE-732 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-26T18:09:58.763Z
Reserved: 2026-06-12T18:42:02.224Z
Link: CVE-2026-54327
Updated: 2026-06-26T18:09:54.757Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T16:05:35Z
Github GHSA