GHSA-5wp8-q9mx-8jx8
CRITICAL[zeptoclaw](https://github.com/qhkm/zeptoclaw) implements a allowlist combined with a blocklist to prevent malicious shell commands in [src/security/shell.rs](https://github.com/qhkm/zeptoclaw/blob/v0.5.8/src/security/shell.rs). However, even in the Strict mode, attackers can completely bypass all the guards from allowlist and blocklist:
- Affected
- >=0, <0.6.2, <= 0.6.1
- Fixed in
- 0.6.2
- Weakness
- CWE-77
- Published
- 2026-03-05
- Source
- osv