CVE-2026-32232CWE-22CWE-62

ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink

High · published March 12, 2026

CVSS v4.0
8.8
EPSS
1%
Percentile
47.4
In the wild
Unconfirmed
What it is

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

The record
Technical detail
CVSS v4.0
8.8 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
0.00618 · 47.4th percentile
Weaknesses
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CWE-62 · UNIX Hard Link
Published
2026-03-12T18:24Z
EPSS history
Timeline
  • 12 MAR 18:24Z
    ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
    cvelistv5