Description
A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a local position. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-28
Score: 2.4 Low
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

A flaw in the isSecurityDefenseSkill function of agentverus-scanner’s context.js allows the application to process untrusted input without proper validation and use that data to make a security decision. This flaw is a CWE‑20 (Improper Input Validation) and CWE‑807 (Untrusted Input Leading to Incorrect Security Decision) vulnerability. As a result a local attacker who can execute code on the host can craft input that makes the scanner treat the request as a legitimate security activity, potentially enabling the attacker to bypass or subvert the scanner’s security checks. The vulnerability does not provide remote code execution or network-level impact but can compromise the integrity of the scanning process and any security decisions that rely on it.

Affected Systems

The affected product is agentverus agentverus‑scanner, versions up to and including 0.8.1. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 2.4 indicates a low severity based on the current description. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The attack vector must be local, which limits the breadth of possible exploitation but still poses a risk to users with local privileges. Because the exploit is publicly available and the maintainer has not yet responded, operators are advised to treat this as a legitimate threat given the potential for local privilege misuse.

Generated by OpenCVE AI on September 28, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install any newer release of agentverus‑scanner that contains a fix for the isSecurityDefenseSkill vulnerability.
  • Configure the scanner process to run under a dedicated, least‑privilege account and restrict local user access to the executable and its directories.
  • If a patch is unavailable, disable the security decision functionality that relies on isSecurityDefenseSkill or remove the component from any production environment until a fix is released.
  • Apply a code‑level patch that validates all inputs to the isSecurityDefenseSkill function against an explicit allowlist before it influences security decisions.

Generated by OpenCVE AI on September 28, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a local position. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Title agentverus agentverus-scanner context.js isSecurityDefenseSkill reliance on untrusted inputs in a security decision
First Time appeared Agentverus
Agentverus agentverus-scanner
Weaknesses CWE-20
CWE-807
CPEs cpe:2.3:a:agentverus:agentverus-scanner:*:*:*:*:*:*:*:*
Vendors & Products Agentverus
Agentverus agentverus-scanner
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 2.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Agentverus Agentverus-scanner
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T15:45:10.884Z

Reserved: 2026-09-27T18:05:22.967Z

Link: CVE-2026-101079

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T16:17:12.590

Modified: 2026-09-28T16:17:12.763

Link: CVE-2026-101079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:47:52Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision