CVE-2026-84809
EUVD-2026-7022402.09.2026, 17:18
Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tencent | ai-infra-guard | 𝑥 < 4.5.2 | CNA |
| tencent | ai-infra-guard | 𝑥 ≤ 4.6.0 | CNA |
| tencent | ai-infra-guard | 𝑥 ≤ 0.2.1 | CNA |
Common Weakness Enumeration