CVE-2026-54325 | earendil-works pi up to 0.78.x project-local Extension inclusion of functionality from untrusted control sphere (GHSA-mqxh-6gq7-558m)

SecurityVulns

A vulnerability marked as problematic has been reported in earendil-works pi up to 0.78.x. Affected by this issue is some unknown functionality of the component project-local Extension. The manipulation leads to inclusion of functionality from untrusted control sphere.

This vulnerability is referenced as CVE-2026-54325. The attack can only be performed from a local environment. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More