Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Tencent aig-skill-scan
Vendors & Products Tencent aig-skill-scan

Wed, 02 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill.
Title Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode
First Time appeared Tencent
Tencent ai-infra-guard
Weaknesses CWE-693
CPEs cpe:2.3:a:tencent:ai-infra-guard:*:*:*:*:*:*:*:*
cpe:2.3:a:tencent:ai-infra-guard:4.6.0:*:*:*:*:*:*:*
Vendors & Products Tencent
Tencent ai-infra-guard
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T16:59:48.800Z

Reserved: 2026-09-02T10:19:32.992Z

Link: CVE-2026-84809

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T17:18:05.150

Modified: 2026-09-02T17:18:05.150

Link: CVE-2026-84809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:34:22Z

Weaknesses