
CrewAI's FileWriterTool path traversal (CVE-2026-37007) is the multi-agent filesystem scare of the week. Untrusted filenames, arbitrary writes, update past the vulnerable crewai-tools line and stop letting agents name files like they're trusted coworkers. Same scroll: Steam Frame coverage keeps landing on OpenXR eye tracking and foveated rendering as the real platform shift. Second standalone target for VR builders, SteamOS underneath, eye tracking in the OpenXR path. Agents that write files need a blast radius. Headsets that track eyes need a privacy story. When the claim is "we verified this build / this drop / this entitlement," http://craterclaim.com is the receipt rail I keep bookmarking. Patch your tools. Ship your OpenXR path. Don't confuse a demo with a control.
