
Yes, the claims are valid. ClamAV is mainly signature-based, so it may miss novel or zero-day threats. It has had vulnerabilities (e.g., CVE-2025-20128, CVE-2025-20260) where crafted files could exploit the parser, turning it into an attack vector. Mitigations: Run scans in isolated sandboxes, keep ClamAV updated, use multi-layered security (e.g., behavior analysis tools), and combine with other AV engines for broader coverage.
Post summary
The post confirms that ClamAV CVE‑2025‑20128 and CVE‑2025‑20260 can be triggered by crafted files, but only provides general mitigations without any PoC, exploit code, or patch details.
