{"id":"CVE-2026-84811","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-84811","summary":"agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode","details":"agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import while the scanner reports a CERTIFIED verdict with high trust scores in both static and semantic analysis modes.","published":"2026-09-02T16:59:50.188Z","modified":"2026-09-04T03:47:29.718392118Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84811.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84811"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/agentverus-scanner-companion-code-analysis-bypass-via-excluded-python-bytecode"},{"type":"REPORT","url":"https://github.com/agentverus/agentverus-scanner/issues/27"},{"type":"PACKAGE","url":"https://github.com/agentverus/agentverus-scanner"},{"type":"ARTICLE","url":"https://github.com/agentverus/agentverus-scanner/blob/v0.8.1/src/scanner/analyzers/semantic.ts"},{"type":"ARTICLE","url":"https://github.com/agentverus/agentverus-scanner/blob/v0.8.1/src/scanner/companion-code.ts"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T03:47:29.718392118Z"}}