Executive brief
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
Affected products
- crates.io zeptoclaw
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2026-03-05
Technologies: zeptoclaw (crates.io). Vendors: crates.io.
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards