CVE-2026-101079 Details
Description
A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a local position. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in AgentVerus Scanner versions up to 0.8.1, specifically within the 'isSecurityDefenseSkill' function in 'dist/scanner/analyzers/context.js'. This vulnerability allows local manipulation that leads to an over-reliance on untrusted inputs for security decisions. By controlling the skill name to include certain security-related terms, a malicious skill can bypass injection findings, creating a false sense of security. This issue has been publicly disclosed.
The vulnerability can be addressed by modifying the scanner to not trust skill metadata for security decisions. Instead, require an external verification signal, such as a registry flag or a signed attestation. At a minimum, ensure that critical injection patterns are always reported, regardless of the skill's defense status.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/agentverus/agentverus-scanner/ | [email protected] | Vendor |
| https://github.com/agentverus/agentverus-scanner/issues/28 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-101079 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/931274 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410950 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410950/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-807 | Reliance on Untrusted Inputs in a Security Decision | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| agentverus agentverus-scanner | <= 0.8.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion