CVE-2026-32232

CRITICAL

ZeptoClaw <0.7.6 - Privilege Escalation

Title source: llm

Description

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 23.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-62 CWE-22
Status published
Products (2)
aisarlabs/zeptoclaw < 0.7.5
crates.io/zeptoclaw 0 - 0.7.6crates.io
Published Mar 12, 2026
Tracked Since Mar 13, 2026