Skip to content
Threat Feed
high advisory

Path Traversal Vulnerability in ZeroClaw Plugin Installation

ZeroClaw versions before 0.8.5 are vulnerable to path traversal via the plugins-wasm feature, allowing attackers to overwrite arbitrary files through crafted plugin manifest files.

CVE search metadata

CVE search record: CVE-2026-101885. Severity: high. CVSS: 7.8. KEV: no. Product: ZeroClaw (< 0.8.5). Brief: Path Traversal Vulnerability in ZeroClaw Plugin Installation. Brief link: https://feed.craftedsignal.io/briefs/2026-09-zeroclaw-path-traversal/

ZeroClaw versions prior to 0.8.5 are susceptible to a path traversal vulnerability when the plugins-wasm feature is enabled. The vulnerability stems from insufficient input validation of the wasm_path field within the plugin manifest file during installation. An attacker can create a malicious plugin containing a crafted manifest file that specifies arbitrary filesystem locations for the plugin component. When a user installs the malicious plugin, the application fails to sanitize this path, resulting in the plugin writing or overwriting files outside the intended plugins directory. This behavior can be leveraged to overwrite sensitive system files or shell configuration scripts, potentially leading to remote code execution under the context of the user running the ZeroClaw application. This issue impacts all platforms where ZeroClaw is deployed if the vulnerable plugins-wasm feature is active.

Impact

Successful exploitation allows for unauthorized file writes on the host system. By targeting shell startup files or other sensitive configuration locations, an attacker can achieve code execution, potentially leading to full system compromise or persistence. This vulnerability poses a high risk to environments where users frequently install third-party plugins from untrusted sources.

Recommendation

  • Upgrade ZeroClaw to version 0.8.5 or later to patch CVE-2026-101885.
  • Disable the plugins-wasm feature if it is not required for operational workflows until the environment can be updated.
  • Implement file integrity monitoring on critical configuration directories and shell startup scripts to detect unauthorized file modifications associated with plugin installation events.

Immediate actions

Upgrade ZeroClaw to version 0.8.5 or later.

IT Operations 48h

Mitigations

Disable plugins-wasm feature in ZeroClaw configuration.

immediate IT Operations

CVE-2026-101885