CVE-2026-32232CWE-22CWE-62
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High · published March 12, 2026
What it is
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.
The record
Technical detail
- CVSS v4.0
- 8.8 · HIGH
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS
- 0.00618 · 47.4th percentile
- Weaknesses
- CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CWE-62 · UNIX Hard Link
- Published
- 2026-03-12T18:24Z
EPSS history
Timeline