PT-2026-20911 · Unknown · Skill-Scanner
Richardoc
·
Published
2026-02-17
·
Updated
2026-03-08
·
CVE-2026-26057
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Skill-scanner versions 1.0.1 and earlier
Description
Skill Scanner is a security scanner for AI Agent Skills designed to detect prompt injection, data exfiltration, and malicious code patterns. A flaw in the API Server component could permit an unauthenticated, remote attacker to interact with the server's API. This interaction could result in a denial-of-service (DoS) condition or the uploading of arbitrary files. The root cause of this issue is an incorrect binding to multiple interfaces. An attacker can exploit this by sending API requests to a device that exposes the affected API Server. A successful exploit could lead to excessive resource consumption (memory starvation) or unauthorized file uploads to arbitrary folders on the compromised device. The API Server is not enabled by default.
Recommendations
Upgrade to Skill-scanner version 1.0.2 or later to resolve this issue.
Exploit
Fix
DoS
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skill-Scanner