Skip to content
Path Traversal Vulnerability in ZeroClaw Plugins

Path Traversal Vulnerability in ZeroClaw Plugins

First seen 1 Oct 2026, 01:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 01:59 UTC
  • •CVE-2026-101885 affects ZeroClaw versions before 0.8.5 with plugins-wasm feature.
  • •Attackers can exploit this flaw to write arbitrary files, enabling potential code execution.
  • •Users should upgrade to version 0.8.5 or disable WASM plugin support to mitigate risks.

A path traversal vulnerability identified as CVE-2026-101885 affects ZeroClaw versions prior to 0.8.5 built with the plugins-wasm feature. This flaw allows attackers to craft malicious plugins that can write arbitrary files outside the designated plugins directory, potentially enabling code execution. The vulnerability arises from the failure to validate the wasm_path manifest field during plugin installation. Users installing untrusted plugins are at high risk, especially on developer workstations and self-hosted environments. A proof-of-concept exists, but there are no confirmed reports of active exploitation. Users are advised to upgrade to version 0.8.5 or disable WASM plugin support if not needed. The CVSS score for this vulnerability is 8.5, categorized as high concern. Mitigation strategies include reviewing plugin manifests and monitoring for unauthorized file changes.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-101885 published
The vulnerability was officially published, highlighting its impact on ZeroClaw versions prior to 0.8.5.
Redpacketsecurity
2026-10-01
ZeroClaw advisory released
GitHub published an advisory detailing the path traversal vulnerability and its implications for users.
github.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-101885 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of ZeroClaw are affected?
ZeroClaw versions prior to 0.8.5 built with the plugins-wasm feature are affected.
Is there a patch available?
Yes, users should upgrade to ZeroClaw version 0.8.5 to mitigate this vulnerability.
What should I do if I can't upgrade immediately?
Disable WASM plugin support and review plugin manifests for any suspicious paths.