CVE-2026-32232: Aisarlabs Zeptoclaw

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

Affected products

  • Aisarlabs Zeptoclaw: up to and including 0.7.5

Published 2026-03-12. Last modified 2026-06-17.