agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign source files. Attackers can execute arbitrary Python bytecode on import while the scanner reports a CERTIFIED verdict with high trust scores in both static and semantic analysis modes.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
agentverus · agentverus-scannerReferences
https://github.com/agentverus/agentverus-scannerhttps://github.com/agentverus/agentverus-scanner/blob/v0.8.1/src/scanner/analyzers/semantic.tshttps://github.com/agentverus/agentverus-scanner/blob/v0.8.1/src/scanner/companion-code.tshttps://github.com/agentverus/agentverus-scanner/issues/27https://www.vulncheck.com/advisories/agentverus-scanner-companion-code-analysis-bypass-via-excluded-python-bytecode