Impact
A flaw in OpenClaw ClawScan’s static_scanner.go causes the static scanner to perform incomplete comparisons by omitting required factors during analysis. The weakness does not allow remote code execution or compromise of the host, but it can lead to inaccurate scanning results or unintended side effects if an attacker manipulates scanner input. The issue is categorized as Local Abuse via Incomplete Comparison and is quantified with a CVSS score of 2.4, indicating low severity in terms of confidentiality, integrity, and availability impact.
Affected Systems
OpenClaw ClawScan versions up to and including 0.1.6 are affected. The problem is resolved in version 0.1.7. The vendor provides a patch with commit ID 9f6a6fbb9f1137345566d0ab44c73893dfe112fa, which is also delivered in the 0.1.7 release.
Risk and Exploitability
The CVSS score of 2.4 classifies the vulnerability as low severity. The EPSS score is reported as < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is local; an attacker with local access can manipulate scanner input to trigger the incomplete comparison. Since the exploit has been publicly published, the risk to environments that run ClawScan locally remains low, but any trusted system using this software should address the flaw promptly.
OpenCVE Enrichment