{"id":"CVE-2026-84811","summary":"agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode","details":"agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import while the scanner reports a CERTIFIED verdict with high trust scores in both static and semantic analysis modes.","modified":"2026-09-04T03:47:29.718392118Z","published":"2026-09-02T16:59:50.188Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84811.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-693"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84811.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84811"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/agentverus-scanner-companion-code-analysis-bypass-via-excluded-python-bytecode"},{"type":"REPORT","url":"https://github.com/agentverus/agentverus-scanner/issues/27"},{"type":"PACKAGE","url":"https://github.com/agentverus/agentverus-scanner"},{"type":"ARTICLE","url":"https://github.com/agentverus/agentverus-scanner/blob/v0.8.1/src/scanner/analyzers/semantic.ts"},{"type":"ARTICLE","url":"https://github.com/agentverus/agentverus-scanner/blob/v0.8.1/src/scanner/companion-code.ts"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/agentverus/agentverus-scanner","events":[{"introduced":"0"},{"last_affected":"8c8636e4c72e518b4755a593831cb079e8ba69d2"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.8.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.8.1","agentverus-scanner-mcp@0.1.2","v0.8.0","v0.7.0","v0.6.2","v0.6.1","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84811.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}