CVE-2026-84810CWE-693

CVE-2026-84810

Medium · published September 2, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
17.8
In the wild
Unconfirmed
What it is

claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, bytecode, and other artifacts in the scripts directory. Attackers can distribute skills with malicious code in non-manifest files that receive a SAFE verdict with 100/100 trust score despite containing unanalyzed executable payloads.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v4.0
7.1 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00262 · 17.8th percentile
Weakness
CWE-693 · Protection Mechanism Failure
Published
2026-09-02T21:18Z
References (6)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 16:59Z
    claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan
    cvelistv5