Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution. | |
| Title | ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T19:55:05.567Z
Reserved: 2026-09-28T15:44:45.389Z
Link: CVE-2026-101885
Updated: 2026-09-30T19:54:47.000Z
Status : Received
Published: 2026-09-30T20:17:21.157
Modified: 2026-09-30T20:17:21.157
Link: CVE-2026-101885
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:30:18Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')