PT-2026-20911 · Unknown · Skill-Scanner

Richardoc

·

Published

2026-02-17

·

Updated

2026-03-08

·

CVE-2026-26057

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Skill-scanner versions 1.0.1 and earlier
Description Skill Scanner is a security scanner for AI Agent Skills designed to detect prompt injection, data exfiltration, and malicious code patterns. A flaw in the API Server component could permit an unauthenticated, remote attacker to interact with the server's API. This interaction could result in a denial-of-service (DoS) condition or the uploading of arbitrary files. The root cause of this issue is an incorrect binding to multiple interfaces. An attacker can exploit this by sending API requests to a device that exposes the affected API Server. A successful exploit could lead to excessive resource consumption (memory starvation) or unauthorized file uploads to arbitrary folders on the compromised device. The API Server is not enabled by default.
Recommendations Upgrade to Skill-scanner version 1.0.2 or later to resolve this issue.

Exploit

Fix

DoS

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2026-26057
GHSA-PPFX-73J5-FHXC

Affected Products

Skill-Scanner