zeptoclaw CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

zeptoclaw vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to zeptoclaw, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-32231 ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to those untrusted values. Because authentication is optional and defaults to disabled (auth_token: None), an attacker who can reach POST /webhook can spoof an allowlisted sender and choose arbitrary chat_id values, enabling high-risk message spoofing and potential IDOR-style session/chat routing abuse. T [email protected] 8.2 0.05% 2026-03-12 2026-03-20
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence