CVE-2026-101885: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in zeroclaw-labs ZeroClaw
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
AI Analysis
Technical Summary
CVE-2026-101885 is a path traversal vulnerability in zeroclaw-labs ZeroClaw versions prior to 0.8.5 when built with the plugins-wasm feature. The issue is due to improper validation of the wasm_path field in plugin manifests during installation. Exploiting this vulnerability, an attacker can craft malicious plugins that write arbitrary files outside the plugins directory, such as shell startup files, which can lead to code execution under the context of the user installing the plugin.
Potential Impact
Successful exploitation allows an attacker to write arbitrary files outside the intended plugin directory, including sensitive locations like shell startup files. This can result in arbitrary code execution when the user starts their shell environment, compromising the user's system integrity and security.
Mitigation Recommendations
Users should upgrade to ZeroClaw version 0.8.5 or later where this vulnerability is fixed. Since the vulnerability affects versions before 0.8.5, applying the official update is the recommended remediation. No vendor advisory content was provided to indicate alternative mitigations or temporary fixes.
CVE-2026-101885: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in zeroclaw-labs ZeroClaw
Description
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
CVSS v4.0
Score 8.5high
Affected software
zeroclaw-labs
ZeroClaw
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-101885 is a path traversal vulnerability in zeroclaw-labs ZeroClaw versions prior to 0.8.5 when built with the plugins-wasm feature. The issue is due to improper validation of the wasm_path field in plugin manifests during installation. Exploiting this vulnerability, an attacker can craft malicious plugins that write arbitrary files outside the plugins directory, such as shell startup files, which can lead to code execution under the context of the user installing the plugin.
Potential Impact
Successful exploitation allows an attacker to write arbitrary files outside the intended plugin directory, including sensitive locations like shell startup files. This can result in arbitrary code execution when the user starts their shell environment, compromising the user's system integrity and security.
Mitigation Recommendations
Users should upgrade to ZeroClaw version 0.8.5 or later where this vulnerability is fixed. Since the vulnerability affects versions before 0.8.5, applying the official update is the recommended remediation. No vendor advisory content was provided to indicate alternative mitigations or temporary fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-28T15:44:45.389Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd640d2a4e24523d7a0fbe
Added to database: 09/30/2026, 19:33:33 UTC
Last enriched: 09/30/2026, 19:47:57 UTC
Last updated: 10/01/2026, 04:45:45 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.