ZeroClaw 0.8.5 之前使用 plugins-wasm 功能构建的版本存在一个路径遍历漏洞,该漏洞位于插件安装过程中,未能对 wasm_path 清单字段进行有效验证。攻击者可以诱骗用户安装经过恶意构造的插件,从而将任意文件写入插件目录之外的路径(例如 shell 启动文件),进而实现代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zeroclaw-labs | ZeroClaw | < 0.8.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zeroclaw-labs | ZeroClaw | 0 ~ 0.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet