CVE-2026-84811: agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode

Published Sep 2, 2026
·
Updated

agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious pycache entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import while the scanner reports a CERTIFIED verdict with high trust scores in both static and semantic analysis modes.

Affected Software

1 affected component
Verus agentverus-scanner

Event History

Sep 2, 2026
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this bypass?

Users who rely on agentverus-scanner to assess companion code directories are exposed when those directories can contain attacker-supplied Python bytecode, including __pycache__ entries. The issue affects both static and semantic analysis modes.

2

What does an attacker need to exploit it?

The attacker needs to ship malicious compiled Python bytecode alongside benign source files in a companion code directory and have that bytecode executed through Python import behavior. No scanner privileges are required, but user interaction is required according to the supplied severity vector.

3

How can teams identify potentially affected scan results?

Review CERTIFIED results with high trust scores for companion code directories that include Python __pycache__ directories or compiled bytecode files. Such files may have been excluded from both static and semantic analysis.

4

What can be done while a fix is unavailable?

Do not treat a CERTIFIED verdict as sufficient for companion code containing Python bytecode. Reject, remove, or independently inspect compiled bytecode and __pycache__ contents before importing or executing the associated code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203