Skip to content
CVE Alert: CVE-2026-101885 – zeroclaw-labs

CVE Alert: CVE-2026-101885 – zeroclaw-labs

Redpacketsecurity •admin • October 1, 2026

ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.

**Risk verdict:** High concern for plugin-enabled deployments: a proof-of-concept indicator is present, but no KEV listing or active-exploitation state is supplied, so urgency is elevated rather than confirmed as emergency.

**Why this matters:** A crafted plugin can turn a routine installation decision into arbitrary file writes, potentially enabling code execution under the installing user’s account. Likely goals include persistence, credential theft, or disrupting the host; impact depends on that account’s access and the files reached. EPSS and deployment prevalence are unavailable, leaving likelihood and fleet-wide exposure uncertain.

**Most likely attack path:** An attacker supplies a malicious plugin and persuades a user to install it. The path is local and low-complexity; the scoring indicates no prior privileges, but user interaction is required. Scope is unchanged, so direct impact is on the ZeroClaw host rather than an independently affected system; lateral movement would depend on stolen credentials or the host’s permissions.

**Who is most exposed:** Hosts built with WASM plugin support and users who install third-party or unreviewed plugins are most exposed. Pay particular attention to developer workstations and self-hosted agent environments.

Alert on plugin installation writing outside its designated directory.

Review plugin manifests for traversal sequences or unexpected absolute paths.

Monitor shell startup files and other persistence locations for changes.

Correlate plugin installation with unexpected child processes or outbound connections.

Mitigation and prioritisation:

Upgrade to a vendor-fixed release; verify the deployed build includes the correction.

Disable WASM plugin support where it is not required.

Restrict plugin sources and review manifests before installation.

Run the service with least privilege; check for unauthorised file changes.

Schedule upgrades with testing for plugin compatibility.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)