CVE-2026-91835

Summary

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version 0.1.7 is sufficient to resolve this issue. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. You should upgrade the affected component.

Affected Software

VendorProductVersion RangeStatus
OpenClawClawScan0.1.0affected
OpenClawClawScan0.1.1affected
OpenClawClawScan0.1.2affected
OpenClawClawScan0.1.3affected
OpenClawClawScan0.1.4affected
OpenClawClawScan0.1.5affected
OpenClawClawScan0.1.6affected
OpenClawClawScan0.1.7unaffected

Weaknesses

  • CWE-436: Interpretation Conflict

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References