---
id: CVE-2026-101079
title: A vulnerability was found in agentverus agentverus-scanner up to 0.8.1
summary: >-
  A vulnerability was found in agentverus agentverus-scanner up to 0.8.1.
  Affected by this vulnerability is the function isSecurityDefenseSkill of the
  file dist/scanner/analyzers/context.js. Performing a manipulation results in
  reliance on…
severity: low
cvss: 2.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-20
  - CWE-807
vendor: agentverus
product: agentverus-scanner
affected:
  - agentverus-scanner 0.8.0
  - agentverus-scanner 0.8.1
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T16:17:12.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101079'
references:
  - url: 'https://github.com/agentverus/agentverus-scanner/'
    label: cna@vuldb.com
  - url: 'https://github.com/agentverus/agentverus-scanner/issues/28'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-101079'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/931274'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410950'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410950/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T16:15:01.370Z'
---

## Overview

A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a local position. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
