Bypass Vulnerability in AgentVerus Scanner Affects Security Analysis of Python Bytecode Files
CVE-2026-84811

7.1HIGH

Key Information:

Vendor

Agentverus

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84811?

The AgentVerus Scanner for Python projects contains a significant bypass issue that allows attackers to circumvent security screenings by concealing malicious compiled Python bytecode within pycache directories alongside legitimate source files. This flaw enables the execution of arbitrary bytecode upon importing, leading the scanner to erroneously certify these files with high trust scores in both static and semantic analysis methodologies. This issue poses a severe risk to developers relying on the scanner for secure code practices, as the security threat remains hidden while being falsely validated.

Affected Version(s)

agentverus-scanner 0 <= 0.8.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nedlir
.