A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the file packages/coding-agent/src/core/extensions/loader.ts. The manipulation leads to code injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept/demo for CVE-2026-5556, showing a Kubernetes admission controller bypass caused by case-sensitive deny-list matching. It contains two code files: a vulnerable Flask admission webhook (admission_webhook.py) and a client exploit script (exploit_admission_bypass.py), plus a README and license. The webhook exposes a POST /validate endpoint over HTTPS on port 443 and denies only exact pod names in DENIED_POD_NAMES, specifically 'kube-system-svc' and 'admin-pod'. The exploit crafts an AdmissionReview-like JSON object containing a pod named 'Admin-Pod' and posts it to https://localhost:443/validate with TLS verification disabled. Because the webhook performs exact case-sensitive comparison, the altered-case pod name is accepted and the response indicates allowed=true. The exploit does not deliver code execution or a shell; its capability is access-control bypass against admission validation logic, enabling unauthorized pod admission in the demonstrated scenario. The repository appears to be a functional PoC rather than a framework module or detection script.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.