PatchSiren

claude-world CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH claude-world CVE published 2026-09-02

CVE-2026-84810

The CVE-2026-84810 vulnerability in claude-skill-antivirus allows attackers to distribute skills with malicious code in non-manifest files that receive a SAFE verdict with 100/100 trust score despite containing unanalyzed executable payloads. This issue arises because the antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, [truncated]