Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill. | |
| Title | Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode | |
| First Time appeared |
Tencent
Tencent ai-infra-guard |
|
| Weaknesses | CWE-693 | |
| CPEs | cpe:2.3:a:tencent:ai-infra-guard:*:*:*:*:*:*:*:* cpe:2.3:a:tencent:ai-infra-guard:4.6.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tencent
Tencent ai-infra-guard |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T16:59:48.800Z
Reserved: 2026-09-02T10:19:32.992Z
Link: CVE-2026-84809
No data.
Status : Received
Published: 2026-09-02T17:18:05.150
Modified: 2026-09-02T17:18:05.150
Link: CVE-2026-84809
No data.
OpenCVE Enrichment
Updated: 2026-09-03T11:30:03Z
Weaknesses