CVE-2026-101885 Details
Description
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
A path traversal vulnerability has been identified in ZeroClaw versions prior to 0.8.5, specifically in builds that include the plugins-wasm feature. This vulnerability arises during the plugin installation process, where the wasm_path manifest field is not properly validated. As a result, attackers can create malicious plugins that, when installed by users, write arbitrary files to locations outside the designated plugins directory. This could include overwriting shell startup files, potentially leading to unauthorized code execution.
Users can upgrade to ZeroClaw version 0.8.5 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ZeroClaw | <= 0.8.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
| Sep 30, 2026 | CVE Modified | CISA-ADP |
Volerion