Analysis Bypass in Claude-Skill-Antivirus Affects Local Executable Files
CVE-2026-84810

7.1HIGH

Key Information:

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84810?

The Claude-Skill-Antivirus application suffers from an analysis bypass vulnerability that prevents it from properly scanning executable files located in local skill directories. Instead of thoroughly evaluating all script artifacts, such as Python source and bytecode, the antivirus tool only analyzes the SKILL.md manifest file. This oversight allows attackers to incorporate harmful code into non-manifest files, which may be granted a misleading SAFE verdict with a perfect trust score of 100/100. Consequently, users may unknowingly execute skills containing malicious payloads due to this inadequate scanning mechanism.

Affected Version(s)

claude-skill-antivirus 0 <= 2.1.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nedlir
.