Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill. | |
| Title | Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode | |
| First Time appeared |
Tencent
Tencent ai-infra-guard |
|
| Weaknesses | CWE-693 | |
| CPEs | cpe:2.3:a:tencent:ai-infra-guard:*:*:*:*:*:*:*:* cpe:2.3:a:tencent:ai-infra-guard:4.6.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tencent
Tencent ai-infra-guard |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T16:59:48.800Z
Reserved: 2026-09-02T10:19:32.992Z
Link: CVE-2026-84809
No data.
Status : Received
Published: 2026-09-02T17:18:05.150
Modified: 2026-09-02T17:18:05.150
Link: CVE-2026-84809
No data.
OpenCVE Enrichment
No data.
-
CWE-693
Protection Mechanism Failure