Impact
ClawScan’s File Classifier contains a flaw in its IsBinaryFile routine, where conflicting logic causes the scanner to incorrectly decide whether a file is binary, as described by CWE‑436. This results in interpretation conflict.
Affected Systems
The vulnerability exists in OpenClaw ClawScan versions up to and including 0.1.6. The fix was released with version 0.1.7, which contains the patch identified by commit 04401337b3adb9343bd338b21e5e258bf49ca9c8.
Risk and Exploitability
The CVSS base score of 2.4 reflects a low severity impact. EPSS score of 0.00113 (approximately 0.1%) indicates a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Exploitation requires local access; public exploit code is available. The risk is confined to local users and mainly affects the accuracy of file classification.
OpenCVE Enrichment