Vulnerability Description
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aisarlabs | Zeptoclaw | <= 0.7.5 |
Related Weaknesses (CWE)
References
- https://github.com/qhkm/zeptoclaw/commit/f50c17e11ae3e2d40c96730abac41974ef2ee2aPatch
- https://github.com/qhkm/zeptoclaw/security/advisories/GHSA-2m67-cxxq-c3h8ExploitPatchVendor Advisory
FAQ
What is CVE-2026-32232?
CVE-2026-32232 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.
How severe is CVE-2026-32232?
CVE-2026-32232 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-32232?
Check the references section above for vendor advisories and patch information. Affected products include: Aisarlabs Zeptoclaw.