Description
A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version 0.1.7 is sufficient to resolve this issue. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. You should upgrade the affected component.
Published: 2026-09-15
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local file misclassification
Action: Upgrade
AI Analysis

Impact

ClawScan’s File Classifier contains a flaw in its IsBinaryFile routine, where conflicting logic causes the scanner to incorrectly decide whether a file is binary, as described by CWE‑436. This results in interpretation conflict.

Affected Systems

The vulnerability exists in OpenClaw ClawScan versions up to and including 0.1.6. The fix was released with version 0.1.7, which contains the patch identified by commit 04401337b3adb9343bd338b21e5e258bf49ca9c8.

Risk and Exploitability

The CVSS base score of 2.4 reflects a low severity impact. EPSS score of 0.00113 (approximately 0.1%) indicates a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Exploitation requires local access; public exploit code is available. The risk is confined to local users and mainly affects the accuracy of file classification.

Generated by OpenCVE AI on September 17, 2026 at 16:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenClaw ClawScan to version 0.1.7 or newer to apply the commit that resolves the parsing conflict.
  • If an immediate upgrade is not feasible, restrict the directories that ClawScan processes to only trusted or internal file sets, preventing untrusted local files from triggering the misclassification logic.
  • Monitor OpenClaw’s release channels and apply subsequent patches as they become available; maintain awareness that the current vulnerability is limited to local access and does not pose a remote threat.

Generated by OpenCVE AI on September 17, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version 0.1.7 is sufficient to resolve this issue. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. You should upgrade the affected component.
Title OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflict
First Time appeared Openclaw
Openclaw clawscan
Weaknesses CWE-436
CPEs cpe:2.3:a:openclaw:clawscan:*:*:*:*:*:*:*:*
Vendors & Products Openclaw
Openclaw clawscan
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 2.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Openclaw Clawscan
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:49:20.004Z

Reserved: 2026-09-15T08:26:29.046Z

Link: CVE-2026-91835

cve-icon Vulnrichment

Updated: 2026-09-15T14:49:15.600Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:32.567

Modified: 2026-09-16T17:53:40.500

Link: CVE-2026-91835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:59:03Z

Weaknesses