Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84810— claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan

Quick assessment

Affected
claude-world claude-skill-antivirus
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

claude-skill-antivirus 在扫描本地技能目录时,无法分析可执行文件:它仅读取 ,却忽略了 目录中的 Python 源代码、字节码及其他产物。 攻击者可以分发包含恶意代码的非清单文件(即未被 列出的文件),这些文件虽然含有未分析的可执行载荷,但系统仍会对其做出“安全”判定,并给出 100/100 的满分信任评分。

CVSS 6.5 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
claude-world claude-skill-antivirus ≤ 2.1.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84810

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan
Source: CVE Program / CVE List V5
Vulnerability Description
claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, bytecode, and other artifacts in the scripts directory. Attackers can distribute skills with malicious code in non-manifest files that receive a SAFE verdict with 100/100 trust score despite containing unanalyzed executable payloads.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
claude-world claude-skill-antivirus 0 ~ 2.1.3 -

II. Public POCs for CVE-2026-84810

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84810

登录查看更多情报信息。

Vendor Advisories for CVE-2026-84810 (1)

Proof of Concept for CVE-2026-84810 (1)

Security Blog Posts for CVE-2026-84810 (1)

Vendor Pages for CVE-2026-84810 (1)

Other References for CVE-2026-84810 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-84810

No comments yet


Leave a comment