CVE-2026-101079
Deferred Deferred - Pending Action

Local Privilege Escalation in AgentVerus Scanner

Vulnerability report for CVE-2026-101079, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a local position. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
agentverus agentverus-scanner to 0.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-807 The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the agentverus-scanner tool up to version 0.8.1. The issue is in the function isSecurityDefenseSkill within the file dist/scanner/analyzers/context.js. An attacker can manipulate the skill name to bypass security checks by using terms like 'guard' or 'sentinel'. This causes the function to suppress security findings, including high-severity threats like data exfiltration, by setting the severity multiplier to zero.

Detection Guidance

Check if agentverus-scanner version 0.8.1 or earlier is installed by running commands like 'agentverus-scanner --version' or inspecting package managers for the tool. Review logs for suppressed security findings where skill names like 'guard' or 'sentinel' may have triggered bypasses in threat-listing contexts.

Impact Analysis

If exploited, this vulnerability could allow attackers to bypass security defenses in AI agents using the agentverus-scanner. This might lead to undetected prompt injections, data exfiltration, or other security threats. Since the attack requires local access, it primarily affects users running vulnerable versions of the scanner.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA by allowing unauthorized data exfiltration or injection attacks to go undetected. Organizations using the vulnerable scanner may fail to meet security requirements for protecting sensitive data.

Mitigation Strategies

Upgrade agentverus-scanner to a patched version if available. Avoid relying on skill names or descriptions for security decisions. Disable suppression of NEVER_REDUCE_PATTERNS even for defense-skill contexts. Monitor for bypass attempts using security-related skill names in threat listings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101079. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart