Intel

AIKIDO-2026-10567

@mariozechner/pi-mom is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 27, 2026

70

High Risk

This Affects:

JS@mariozechner/pi-mom
0.31.0 - 0.68.0
Fixed in 0.69.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS) due to the markdown parser not filtering dangerous URL protocols, so malicious markdown like (javascript:alert(1)) would render as executable code. in the renderResultImages and renderEntry functions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@mariozechner/pi-mom is vulnerable to Cross-site Scripting (XSS) in versions 0.31.0 - 0.68.0.

How to fix this

Upgrade the @mariozechner/pi-mom library to the patch version.