Skip to content

feat: AVE-2026-00075 -- bytecode poisoning (compiled cache/source divergence) - #138

Merged
chaksaray merged 1 commit into
developfrom
ave-00075-bytecode-poisoning
Aug 7, 2026
Merged

chaksaray merged 1 commit into
developfrom
ave-00075-bytecode-poisoning

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Summary

  • Adds AVE-2026-00075: a skill ships a compiled .pyc bytecode file alongside its own .py source, and the compiled bytecode contains dangerous primitives (process execution, network calls, credential-path access) absent from the visible source text. CPython prefers a valid cached .pyc over recompiling its source whenever the header validates, so whatever the .pyc actually contains is what runs -- a reviewer or source-only scanner sees only the benign .py.
  • Distinct from AVE-2026-00057 (obfuscated/encoded skill payload): 00057 is a single artifact whose own content is encoded, requiring a decode-then-rescan step to see the same payload the scanner already has. This is a two-artifact divergence -- the payload isn't present, encoded or otherwise, anywhere the scanner looks, because it's only in the compiled sibling.
  • Verified via keyword sweep (matched AVE-2026-00057 on the word "bytecode"), field-level comparison confirming the mechanisms diverge (single-artifact content obfuscation vs. two-artifact compiled/source divergence via interpreter cache precedence), and by reading the actual repo-forensics scanner source, not just its README:
  • Severity MEDIUM, AIVSS 4.4 (cvss_base 7.5, aars 3.0, mitigation_factor 0.83 -- recompiling from source and refusing untrusted .pyc/__pycache__ content is a known, practical mitigation).
  • mitre_atlas researched and left empty rather than force-fit: AML.T0010.001 (AI Software) and AML.T0010.003 (Model) are adjacent but neither names a compiled-bytecode-cache-diverging-from-its-own-source mechanism specifically.
  • Builds on feat: AVE-2026-00074 -- reclaimable dead external anchor (SkillJacking) #135 (AVE-2026-00074, already merged).

Test plan

  • python3 scripts/validate_records.py -- 75/75 records valid
  • python3 scripts/check_fixtures.py -- all records have positive + negative fixtures
  • pytest tests/ -x -q -- 301 passed
  • node scripts/build-records.js -- dist regenerated, frozen v1.1.0 snapshot untouched
  • README record count (badge, Stats table, collapsible index) and CHANGELOG updated

…ivergence)

CPython prefers a valid cached .pyc over recompiling its own .py
source, so a bundled compiled-bytecode file can contain dangerous
primitives (process execution, network calls, credential-path access)
absent from the source text a reviewer or static scanner actually
reads. Distinct from AVE-2026-00057 (obfuscated/encoded skill
payload), a single-artifact encoding class requiring a decode-then-
rescan step: this is a two-artifact divergence between a compiled
cache and its own sibling source, where the payload isn't present,
encoded or otherwise, anywhere the scanner looks. Sourced from
repo-forensics' scan_bytecode.py and the 2026-06-10 CSA/Trail of Bits
research note demonstrating env-var exfiltration hidden in precompiled
bytecode shipped next to a benign-looking skill.
@chaksaray
chaksaray merged commit ca05ec6 into develop Aug 7, 2026
6 checks passed
@chaksaray
chaksaray deleted the ave-00075-bytecode-poisoning branch August 7, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant