What happened
NVD published CVE-2026-105161 (CVSS 5.3 v3.1 / 6.9 v4.0 via VulDB) on 2026-10-04 for improper cryptographic signature verification in the Policy Gate Handler of invariant-systems-ai aiir up to 1.7.0. The advisory notes the GitHub repository is no longer available and the product is no longer supported by the maintainer.
Why it matters
aiir is an AI 'policy gate' component — the kind of control meant to decide whether an agent's tool calls are allowed. A signature-verification weakness in such a gate undermines the enforcement point for agent actions, but the sole finding is a deprecated, unsupported, low-blast-radius package with no usable exploit, so it is kept for precision rather than urgency.
Attack vector
Remote manipulation of the Policy Gate Handler component bypasses proper verification of the cryptographic signature, so a request with an invalid/forged signature can be accepted through the AI policy gate (CWE-345/347).
Affected systems
invariant-systems-ai aiir 1.0 through 1.7.0 (unsupported; repo removed)
Mitigation
No fix available — the repository is gone and the project is unsupported. Replace the library with a maintained alternative; treat any deployments as unmaintained.