Impact
A flaw in the isSecurityDefenseSkill function of agentverus-scanner’s context.js allows the application to process untrusted input without proper validation and use that data to make a security decision. This flaw is a CWE‑20 (Improper Input Validation) and CWE‑807 (Untrusted Input Leading to Incorrect Security Decision) vulnerability. As a result a local attacker who can execute code on the host can craft input that makes the scanner treat the request as a legitimate security activity, potentially enabling the attacker to bypass or subvert the scanner’s security checks. The vulnerability does not provide remote code execution or network-level impact but can compromise the integrity of the scanning process and any security decisions that rely on it.
Affected Systems
The affected product is agentverus agentverus‑scanner, versions up to and including 0.8.1. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 2.4 indicates a low severity based on the current description. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The attack vector must be local, which limits the breadth of possible exploitation but still poses a risk to users with local privileges. Because the exploit is publicly available and the maintainer has not yet responded, operators are advised to treat this as a legitimate threat given the potential for local privilege misuse.
OpenCVE Enrichment