Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill. | |
| Title | Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode | |
| First Time appeared |
Tencent
Tencent ai-infra-guard |
|
| Weaknesses | CWE-693 | |
| CPEs | cpe:2.3:a:tencent:ai-infra-guard:*:*:*:*:*:*:*:* cpe:2.3:a:tencent:ai-infra-guard:4.6.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tencent
Tencent ai-infra-guard |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T16:59:48.800Z
Reserved: 2026-09-02T10:19:32.992Z
Link: CVE-2026-84809
No data.
Status : Received
Published: 2026-09-02T17:18:05.150
Modified: 2026-09-02T17:18:05.150
Link: CVE-2026-84809
No data.
OpenCVE Enrichment
Updated: 2026-09-03T11:30:03Z
Weaknesses