CVE-2026-32232

CRITICAL WAF: High
CVSS 9.8 Published: 2026-03-12
CWE-22

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

WAF Coverage Analysis

Path Traversal High WAF Coverage

OWASP: A01:2021 Broken Access Control

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
aisarlabszeptoclawup to 0.7.5

References

Back to CVE Database