Vulnerability  ·  2026-10-06

invariant-systems-ai aiir MCP policy-gate improper cryptographic signature verification (CVE-2026-105161)

VulnerabilityLow impactGlobalCVE-2026-105161
NVD published CVE-2026-105161 (CVSS 5.3 v3.1 / 6.9 v4.0 via VulDB) on 2026-10-04 for improper cryptographic signature verification in the Policy Gate Handler of invariant-systems-ai aiir up to 1.7.0. The advisory notes the GitHub repository is no longer available and the product is no longer supported by the maintainer.
aiir is an AI 'policy gate' component — the kind of control meant to decide whether an agent's tool calls are allowed. A signature-verification weakness in such a gate undermines the enforcement point for agent actions, but the sole finding is a deprecated, unsupported, low-blast-radius package with no usable exploit, so it is kept for precision rather than urgency.
Remote manipulation of the Policy Gate Handler component bypasses proper verification of the cryptographic signature, so a request with an invalid/forged signature can be accepted through the AI policy gate (CWE-345/347).
invariant-systems-ai aiir 1.0 through 1.7.0 (unsupported; repo removed)
No fix available — the repository is gone and the project is unsupported. Replace the library with a maintained alternative; treat any deployments as unmaintained.
NVD (cite)GitHub Advisory GHSA-73p9-6hrp-8qhr
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →