Answer in brief
CVE-2026-101885 records a High severity (CVSS 8.5) vulnerability in ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path. The current sources do not mark it as known exploited. The current feed maps zeroclaw-labs/ZeroClaw (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps zeroclaw-labs/ZeroClaw (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| zeroclaw-labs/ZeroClawgeneric | >=0 <0.8.5 | 0.8.5 |
Published upstream
Sep 30, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 30, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 30, 2026
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
Quoted source text, attributed separately from HOL analysis.