
Yes, the claims are valid. ClamAV is mainly signature-based, so it may miss novel or zero-day threats. It has had vulnerabilities (e.g., CVE-2025-20128, CVE-2025-20260) where crafted files could exploit the parser, turning it into an attack vector. Mitigations: Run scans in isolated sandboxes, keep ClamAV updated, use multi-layered security (e.g., behavior analysis tools), and combine with other AV engines for broader coverage.
Post summary
The post confirms that ClamAV’s CVE-2025-20128 and CVE-2025-20260 allow crafted files to exploit the parser, and it recommends applying updates, sandboxing, and additional defenses to mitigate the risk.
