{"id":"CVE-2026-101885","title":"ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field","summary":"ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins tha…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"zeroclaw-labs","product":"ZeroClaw","affected":["ZeroClaw < 0.8.5"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T20:17:21.157","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101885","references":[{"url":"https://github.com/zeroclaw-labs/zeroclaw/blob/v0.8.4/crates/zeroclaw-plugins/src/host.rs#L238-L273","label":"disclosure@vulncheck.com"},{"url":"https://github.com/zeroclaw-labs/zeroclaw/commit/432e034d3cb024610d5916a2f328678d151c1dd5","label":"disclosure@vulncheck.com"},{"url":"https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.8.5","label":"disclosure@vulncheck.com"},{"url":"https://github.com/zeroclaw-labs/zeroclaw/security/advisories/GHSA-93f6-34w8-5g98","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zeroclaw-before-0.8.5-path-traversal-via-plugin-manifest-wasm-path","label":"disclosure@vulncheck.com"},{"url":"https://github.com/zeroclaw-labs/zeroclaw/security/advisories/GHSA-93f6-34w8-5g98","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-30T19:54:26.896752Z"},"ingestedAt":"2026-09-30T20:23:19.513Z","slug":"CVE-2026-101885","body":"## Overview\n\nZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}