Executive brief
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
Affected products
- crates.io zeptoclaw
Junglewise Threat Intelligence
CVE-2026-32231 · Severity: low · CVSS 3.1 · Published 2026-03-12
Technologies: zeptoclaw (crates.io). Vendors: crates.io.
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data