{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azeroclawzeroclaw/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zeroclaw:zeroclaw:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-101885"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZeroClaw (\u003c 0.8.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["ZeroClaw"],"content_html":"\u003cp\u003eZeroClaw versions prior to 0.8.5 are susceptible to a path traversal vulnerability when the plugins-wasm feature is enabled. The vulnerability stems from insufficient input validation of the wasm_path field within the plugin manifest file during installation. An attacker can create a malicious plugin containing a crafted manifest file that specifies arbitrary filesystem locations for the plugin component. When a user installs the malicious plugin, the application fails to sanitize this path, resulting in the plugin writing or overwriting files outside the intended plugins directory. This behavior can be leveraged to overwrite sensitive system files or shell configuration scripts, potentially leading to remote code execution under the context of the user running the ZeroClaw application. This issue impacts all platforms where ZeroClaw is deployed if the vulnerable plugins-wasm feature is active.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized file writes on the host system. By targeting shell startup files or other sensitive configuration locations, an attacker can achieve code execution, potentially leading to full system compromise or persistence. This vulnerability poses a high risk to environments where users frequently install third-party plugins from untrusted sources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade ZeroClaw to version 0.8.5 or later to patch CVE-2026-101885.\u003c/li\u003e\n\u003cli\u003eDisable the plugins-wasm feature if it is not required for operational workflows until the environment can be updated.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring on critical configuration directories and shell startup scripts to detect unauthorized file modifications associated with plugin installation events.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T20:36:55Z","date_published":"2026-09-30T20:36:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zeroclaw-path-traversal/","summary":"ZeroClaw versions before 0.8.5 are vulnerable to path traversal via the plugins-wasm feature, allowing attackers to overwrite arbitrary files through crafted plugin manifest files.","title":"Path Traversal Vulnerability in ZeroClaw Plugin Installation","url":"https://feed.craftedsignal.io/briefs/2026-09-zeroclaw-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zeroclaw:zeroclaw:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}