Path Traversal Vulnerability in ZeroClaw Plugins
Article Content
- •CVE-2026-101885 affects ZeroClaw versions before 0.8.5 with plugins-wasm feature.
- •Attackers can exploit this flaw to write arbitrary files, enabling potential code execution.
- •Users should upgrade to version 0.8.5 or disable WASM plugin support to mitigate risks.
A path traversal vulnerability identified as CVE-2026-101885 affects ZeroClaw versions prior to 0.8.5 built with the plugins-wasm feature. This flaw allows attackers to craft malicious plugins that can write arbitrary files outside the designated plugins directory, potentially enabling code execution. The vulnerability arises from the failure to validate the wasm_path manifest field during plugin installation. Users installing untrusted plugins are at high risk, especially on developer workstations and self-hosted environments. A proof-of-concept exists, but there are no confirmed reports of active exploitation. Users are advised to upgrade to version 0.8.5 or disable WASM plugin support if not needed. The CVSS score for this vulnerability is 8.5, categorized as high concern. Mitigation strategies include reviewing plugin manifests and monitoring for unauthorized file changes.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-101885 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of ZeroClaw are affected?
Is there a patch available?
What should I do if I can't upgrade immediately?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…