HIGHcrates.io
GHSA-2m67-cxxq-c3h8· CVE-2026-32232ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
Modified: 3/14/2026
package
pkg:crates.io/zeptoclaw
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
Modified: 3/14/2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
Modified: 3/13/2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
Modified: 3/14/2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
Modified: 3/5/2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
Modified: 3/5/2026