zeptoclaw
crates.io2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zeptoclawpage 1 of 1
- CVE-2026-32231HIGHCVSS 8.2EG 8.2✓ Fixed in 0.7.62026-03-12
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to those untrusted values. Because authentica…
- CVE-2026-32232CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.7.62026-03-12
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.
Check whether zeptoclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zeptoclaw CVEs against the assets you own.
Start Free Scan →