Repository navigation
Security: agegr/pi-web
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
DNS-rebinding bypass of the v0.8.1 cross-origin API guard re-enables unauthenticated RCE via /api/skills/install (loopback bind affected)GHSA-27c4-4q39-ph85 published
Oct 8, 2026 by agegrHigh -
Unauthenticated CSRF-able remote code execution via POST /api/skills/install (all-interfaces default bind) in pi-web <= 0.8.0GHSA-2gf4-x3m8-rh6x published
Oct 8, 2026 by agegrHigh
Learn more about advisories related to agegr/pi-web in the GitHub Advisory Database