CVE-2026-84811

Source
https://cve.org/CVERecord?id=CVE-2026-84811
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84811.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84811
Published
2026-09-02T16:59:50.188Z
Modified
2026-09-04T03:47:29.718392118Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode
Details

agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious pycache entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import while the scanner reports a CERTIFIED verdict with high trust scores in both static and semantic analysis modes.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84811.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-693"
    ]
}
References

Affected packages

Git / github.com/agentverus/agentverus-scanner

Affected ranges

Type
GIT
Repo
https://github.com/agentverus/agentverus-scanner
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.8.1"
        }
    ]
}

Affected versions

agentverus-scanner-mcp@0.*
agentverus-scanner-mcp@0.1.2
v0.*
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.8.0
v0.8.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84811.json"