CVE-2026-84811: Agentverus Agentverus-Scanner

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import while the scanner reports a CERTIFIED verdict with high trust scores in both static and semantic analysis modes.

Affected products

  • Agentverus Agentverus-Scanner: up to and including 0.8.1

Published 2026-09-02. Last modified 2026-09-23.