CVE-2026-84811

agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import while the scanner reports a CERTIFIED verdict with high trust scores in both static and semantic analysis modes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 17:18

Updated : 2026-09-03 15:17


NVD link : CVE-2026-84811

Mitre link : CVE-2026-84811

CVE.ORG link : CVE-2026-84811


JSON object : View

Products Affected

No product.

CWE
CWE-693

Protection Mechanism Failure