CVE-2026-84809: Tencent Ai-Infra-Guard

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill.

Affected products

  • Tencent Ai-Infra-Guard: before 4.5.2 (fixed in 4.5.2); from 4.6.0, up to and including 4.6.0
  • Tencent Aig-Skill-Scan: up to and including 0.2.1

Published 2026-09-02. Last modified 2026-09-24.