RuleId: CVE-2026-32232
RuleDesc: CVE context for keyword 'ZeptoClaw' // CWE info: CWE-22 (Path Traversal), CWE-62

Vuln Description:
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component
Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is
fixed in 0.7.6.

Metadata:
- Repository hint: https://github.com/qhkm/zeptoclaw
- Published at: 2026-03-12T19:16:17.263
- Severity: CRITICAL (score=9.8)
- Affected summary: aisarlabs:zeptoclaw <=0.7.5

Related Files:
Use CT-graph history, commit metadata, and referenced URLs to identify the exact files,
functions, or symbols that introduced and later fixed this vulnerability in the target repository.

Reference URLs (from CVE dataset):
- [01] https://github.com/qhkm/zeptoclaw/commit/f50c17e11ae3e2d40c96730abac41974ef2ee2a8
- [02] https://github.com/qhkm/zeptoclaw/security/advisories/GHSA-2m67-cxxq-c3h8