Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

@agentos-software/pi bundles @mariozechner/pi-coding-agent 0.60.0, affected by GHSA-jfgx-wxx8-mp94 (fixed only in @earendil-works/pi-coding-agent 0.78.1+)

Đang mở
#2,008 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
45/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
javascript
Lĩnh vực
backend, security

Hướng nghiên cứu

Start with dist/adapter.js and dist/sdk-snapshot.js, then inspect the current adapter imports and package references. Build the package against @earendil-works/pi-coding-agent and @earendil-works/pi-ai at 0.78.1 or newer, update the changed async auth APIs, and verify the published bundle no longer runs the vulnerable @mariozechner packages.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Summary

@agentos-software/pi (checked 0.2.7 and the latest, 0.3.2) depends on and bundles @mariozechner/[email protected] (and @mariozechner/[email protected]) into dist/sdk-snapshot.js. That package line stopped at 0.73.1: Pi moved to @earendil-works/pi-coding-agent, and these advisories list no fix for the @mariozechner name:

Advisory Severity Affected @mariozechner/pi-coding-agent Fixed
GHSA-jfgx-wxx8-mp94 (CVE-2026-54328) — predictable temporary extension install paths, local privilege escalation on shared Linux hosts High >= 0.50.0, <= 0.73.1 @earendil-works/pi-coding-agent 0.78.1
GHSA-7v5m-pr3q-6453 (CVE-2026-54326) — XSS in HTML session exports Low >= 0.27.5, <= 0.73.1 same
GHSA-r95r-rj6r-c39x (CVE-2026-54327) — auth.json write race Low >= 0.28.0, <= 0.73.1 same

Downstream scanners flag every consumer, and an npm overrides entry is not a workaround: the adapter prefers the bundled snapshot (if (snapshotRuntime) in dist/adapter.js), so overriding the dependency changes only the lockfile, not what runs.

Request

Publish an @agentos-software/pi built on @earendil-works/pi-coding-agent / @earendil-works/pi-ai >= 0.78.1. Note the adapter imports internal paths (dist/core/sdk.js, session-manager.js, model-registry.js, ...) and @mariozechner/pi-agent-core; those still exist under the new package names, but the auth APIs changed (e.g. AuthStorage is no longer exported from the package root and credential operations are async).

Related: #1903.

Ngôn ngữ chính
Rust
Star
4.7k
Fork
263
Merge trung bình
8 giờ 57 phút
Pull request đã merge (30 ngày)
30

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của rivet-dev/agentos

Tất cả issue của rivet-dev/agentos

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.