zeptoclaw
Activity
- Latest release
- 5mo ago
- Total releases
- 26
- Cadence
- ~daily
- Last 12 months
- 26
Details
- License
- Apache-2.0
- First release
- Feb 14, 2026
| Version | Released | |
|---|---|---|
0.9.2
unknown
|
0.9.2
unknown
Dependencies (76)
+ 68 more |
|
0.9.1
unknown
|
0.9.1
unknown
Dependencies (76)
+ 68 more |
|
0.9.0
unknown
|
0.9.0
unknown
Dependencies (76)
+ 68 more |
|
0.8.2
unknown
|
0.8.2
unknown
Dependencies (74)
+ 66 more |
|
0.8.1
unknown
|
0.8.1
unknown
Dependencies (74)
+ 66 more |
|
0.8.0
unknown
|
0.8.0
unknown
Dependencies (72)
+ 64 more |
|
0.7.6
unknown
|
0.7.6
unknown
Dependencies (71)
+ 63 more |
|
0.7.5
unknown
3 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev |
0.7.5
unknown
Dependencies (69)
+ 61 more |
|
0.7.4
unknown
3 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev |
0.7.4
unknown
Dependencies (69)
+ 61 more |
|
0.7.3
unknown
3 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev |
0.7.3
unknown
Dependencies (64)
+ 56 more |
|
0.7.2
unknown
3 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev |
0.7.2
unknown
Dependencies (64)
+ 56 more |
|
0.7.1
unknown
3 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev |
0.7.1
unknown
Dependencies (63)
+ 55 more |
|
0.7.0
unknown
3 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev |
0.7.0
unknown
Dependencies (63)
+ 55 more |
|
0.6.2
unknown
3 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev |
0.6.2
unknown
Dependencies (63)
+ 55 more |
|
0.6.1
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.6.1
unknown
Dependencies (62)
+ 54 more |
|
0.6.0
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (51)
+ 43 more |
|
0.5.9
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.5.9
unknown
Dependencies (51)
+ 43 more |
|
0.5.8
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.5.8
unknown
Dependencies (50)
+ 42 more |
|
0.5.7
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.5.7
unknown
Dependencies (50)
+ 42 more |
|
0.5.5
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.5.5
unknown
Dependencies (50)
+ 42 more |
|
0.5.4
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.5.4
unknown
Dependencies (50)
+ 42 more |
|
0.5.3
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.5.3
unknown
Dependencies (50)
+ 42 more |
|
0.5.1
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.5.1
unknown
Dependencies (49)
+ 41 more |
|
0.4.0
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (30)
+ 22 more |
|
0.3.1
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.3.1
unknown
Dependencies (26)
+ 18 more |
|
0.3.0
unknown
5 CVEs
GHSA-4cm8-xpfv-jv6f
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
SummaryThe email channel authorizes senders based on the parsed DetailsRelevant code paths:
Result:
PoC
Impact
Patch RecommendationAdd a sender-authentication gate in Fixed in
0.7.6
References Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32232
GHSA-2m67-cxxq-c3h8
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
Network
Low
None
None
SummaryWorkspace boundary enforcement currently has three related bypass risks. This issue tracks fixing all three in one pull request. DetailsR1 - Dangling Symlink Component Bypass
R2 - TOCTOU Between Validation and Use
R3 - Hardlink Alias Bypass
Risk Matrix| ID | Risk | Severity | Likelihood | Impact | |---|---|---|---|---| | R1 | Dangling symlink component bypass | High | Medium | Workspace boundary escape for read/write | | R2 | Validate/use TOCTOU race | High | Medium | Race-based boundary escape during file I/O | | R3 | Hardlink alias bypass | Medium | Low-Medium | External inode read/write through in-workspace path | PoCR1 - Dangling symlink component bypass
R2 - TOCTOU between validation and use
R3 - Hardlink alias bypass
ImpactsUnauthorized cross path boundary CreditPatchFixed in
0.7.6
References
Updated Mar 14, 2026 · Source: OSV.dev
CVE-2026-32231
GHSA-46q5-g3j9-wx5c
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
8.2
/ 10
High
Network
Low
None
None
Unchanged
Low
High
None
SummaryThe generic webhook channel trusts caller-supplied identity fields ( DetailsRelevant code paths:
Why this is vulnerable:
PoC
Impact
Fixed in
0.7.6
References
Updated Mar 13, 2026 · Source: OSV.dev
GHSA-5wp8-q9mx-8jx8
Mar 05, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Summaryzeptoclaw implements a allowlist combined with a blocklist to prevent malicious shell commands in src/security/shell.rs. However, even in the
DetailsIn code src/security/shell.rs#L218-L243, one can see the allowlist only checks the first token and thus makes command injection possible.
As the code in src/security/shell.rs#L18-L70, we can find the
PoC
ImpactUnauthorized command execution. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev
GHSA-hhjv-jq77-cmvx
Mar 05, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summaryzeptoclaw implements a blocklist to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as DetailsAs in code src/tools/android/actions.rs#L413-L424, we can see the
PoCSet up zeptoclaw with an Android tool and then run the command ImpactUnauthorized command executed in Android device. CreditFixed in
0.6.2
References
Updated Mar 05, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (26)
+ 18 more |