Skip to content

ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data

High severity GitHub Reviewed Published Mar 11, 2026 in qhkm/zeptoclaw • Updated Mar 13, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts