Impact
The vulnerability in badlogic pi-mono, located in the discoverAndLoadExtensions function of loader.ts, allows attackers to inject arbitrary code through manipulated input. This can lead to remote code execution, compromising the confidentiality, integrity, and availability of the affected system. The weakness corresponds to code injection (CWE-74) and potentially code execution (CWE-94).
Affected Systems
badlogic pi-mono, versions up to 0.58.4 are affected. Any deployment of the coding-agent component that imports extensions via loader.ts may be vulnerable. Those running the 0.58.4 release or earlier need to upgrade.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is published, and the vendor has not released a patch yet. Remote exploitation has been confirmed publicly, so the risk remains real for systems still on vulnerable versions. Attackers can target the application over a network or exposed service that uses discoverAndLoadExtensions, and can subsequently execute arbitrary code.
OpenCVE Enrichment