PatchSiren

invariant-systems-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM invariant-systems-ai CVE published 2026-10-04

CVE-2026-105161

A medium-severity vulnerability was found in the Policy Gate Handler of invariant-systems-ai aiir up to 1.7.0, allowing for improper verification of cryptographic signatures. The attack can be executed remotely. However, the GitHub repository for this project is no longer available, and the vulnerability only affects products that are no longer supported by the maintainer.