feat: AVE-2026-00075 -- bytecode poisoning (compiled cache/source divergence) - #138
Merged
Merged
Conversation
…ivergence) CPython prefers a valid cached .pyc over recompiling its own .py source, so a bundled compiled-bytecode file can contain dangerous primitives (process execution, network calls, credential-path access) absent from the source text a reviewer or static scanner actually reads. Distinct from AVE-2026-00057 (obfuscated/encoded skill payload), a single-artifact encoding class requiring a decode-then- rescan step: this is a two-artifact divergence between a compiled cache and its own sibling source, where the payload isn't present, encoded or otherwise, anywhere the scanner looks. Sourced from repo-forensics' scan_bytecode.py and the 2026-06-10 CSA/Trail of Bits research note demonstrating env-var exfiltration hidden in precompiled bytecode shipped next to a benign-looking skill.
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.pycbytecode file alongside its own.pysource, and the compiled bytecode contains dangerous primitives (process execution, network calls, credential-path access) absent from the visible source text. CPython prefers a valid cached.pycover recompiling its source whenever the header validates, so whatever the.pycactually contains is what runs -- a reviewer or source-only scanner sees only the benign.py.scan_bytecode.py-- unmarshals/disassembles.pycfiles in an isolated subprocess and diffs a fixed danger-primitive marker list against the sibling source (_poison_markers_vs_source).cvss_base7.5,aars3.0,mitigation_factor0.83 -- recompiling from source and refusing untrusted.pyc/__pycache__content is a known, practical mitigation).mitre_atlasresearched and left empty rather than force-fit: AML.T0010.001 (AI Software) and AML.T0010.003 (Model) are adjacent but neither names a compiled-bytecode-cache-diverging-from-its-own-source mechanism specifically.Test plan
python3 scripts/validate_records.py-- 75/75 records validpython3 scripts/check_fixtures.py-- all records have positive + negative fixturespytest tests/ -x -q-- 301 passednode scripts/build-records.js-- dist regenerated, frozen v1.1.0 snapshot untouched