
CVE-2026-32231 ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and a… https://www.cve.org/CVERecord?id=CVE-2026-32231
Post summary
The CVE-2026-32231 disclosure reveals that ZeptoClaw versions before 0.7.6 improperly trust caller‑supplied identity fields in webhook requests, potentially enabling impersonation; no PoC, exploit code, or patch details are provided.

