๐Ÿ” CVE Alert

CVE-2026-101885

HIGH 7.8

ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.

CWE CWE-22
Vendor zeroclaw-labs
Product zeroclaw
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for zeroclaw-labs zeroclaw

Be the first to know when new high vulnerabilities affecting zeroclaw-labs zeroclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

zeroclaw-labs / ZeroClaw
0 < 0.8.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zeroclaw-labs/zeroclaw/security/advisories/GHSA-93f6-34w8-5g98 github.com: https://github.com/zeroclaw-labs/zeroclaw/commit/432e034d3cb024610d5916a2f328678d151c1dd5 github.com: https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.8.5 github.com: https://github.com/zeroclaw-labs/zeroclaw/blob/v0.8.4/crates/zeroclaw-plugins/src/host.rs#L238-L273 vulncheck.com: https://www.vulncheck.com/advisories/zeroclaw-before-0.8.5-path-traversal-via-plugin-manifest-wasm-path

Credits

Cameron Beeley (anagnorisis2peripeteia)