Vendor
ZeroClaw versions before 0.8.5 are vulnerable to path traversal via the plugins-wasm feature, allowing attackers to overwrite arbitrary files through crafted plugin manifest files.