Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32231

26
FAUCET Score

CVE-2026-32231 identifies a high-severity vulnerability in ZeptoClaw, a personal AI assistant, affecting versions prior to 0.7.6. This flaw allows an unauthenticated attacker to spoof identity fields (sender, chat_id) via the generic webhook channel, which improperly trusts caller-supplied values. With a CVSS score of 8.2 (High), this can lead to high-risk message spoofing and potential session/chat routing abuse due to compromised data integrity. The attack requires no privileges or user interaction and can be executed over the network. Currently, there is no evidence of active exploitation, nor are public exploit codes or significant community discussion available for this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.7.5CPE matchmatch criteria
cpe:2.3:a:zeptoclaw:zeptoclaw:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 0th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

rustpatch availablevia ghsa
Product: zeptoclawFixed in: 0.7.6

Vendor Advisories (1)

rustGHSA-46q5-g3j9-wx5chigh

ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data

Mar 12, 2026

References

github.com / qhkm/zeptoclaw/commit/bf004a20d3687a0c1a9e052ec79536e30d6de134
Patch
github.com / qhkm/zeptoclaw/pull/324
Issue TrackingPatch
github.com / qhkm/zeptoclaw/releases/tag/v0.7.6
PatchRelease Notes
github.com / qhkm/zeptoclaw/security/advisories/GHSA-46q5-g3j9-wx5c
ExploitVendor Advisory