Impact
ZeroClaw versions built with the plugins-wasm feature validate the wasm_path field of a plugin’s manifest incorrectly. A malicious plugin can use this flaw to write files to arbitrary locations outside the intended plugins directory. Attackers who persuade users to install such a crafted plugin can place executable or startup files, enabling arbitrary code execution on the victim’s system.
Affected Systems
The vulnerability affects ZeroClaw by zeroclaw-labs, specifically any version before 0.8.5 that is compiled with the plugins-wasm feature. Users running those pre‑0.8.5 releases are at risk if they install or remotely fetch plugins that include a crafted wasm_path field.
Risk and Exploitability
The CVSS score for this issue is 8.5, indicating high severity, and the EPSS score is not published. It is not listed in the CISA KEV catalog. The attack requires a user to install a malicious plugin, so it largely depends on social engineering or compromised plugin repositories. Once a plugin is installed, the lack of validation allows the attacker to write files outside the plugin directory—such as shell startup scripts—thereby enabling code execution on the victim’s machine.
OpenCVE Enrichment