CVE-2026-91835 Details
Description
A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version 0.1.7 is sufficient to resolve this issue. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. You should upgrade the affected component.
A vulnerability exists in OpenClaw ClawScan versions through 0.1.6, specifically within the File Classifier component. The issue arises in the 'IsBinaryFile' function, located in 'internal/runner/static_scanner.go'. The vulnerability allows a single null byte to be injected into the first 8 KB of a file, causing the scanner to misclassify the file as binary. This misclassification bypasses all static analysis, leaving potentially malicious content undetected. The vulnerability requires local exploitation.
Users should upgrade to OpenClaw ClawScan version 0.1.7 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/clawscan/ | [email protected] | ProductVendor |
| https://github.com/openclaw/clawscan/commit/04401337b3adb9343bd338b21e5e258bf49ca9c8 | [email protected] | Source CodeVendor |
| https://github.com/openclaw/clawscan/issues/42 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/openclaw/clawscan/pull/43 | [email protected] | Issue TrackingVendor |
| https://github.com/openclaw/clawscan/releases/tag/v0.1.7 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-91835 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/933532 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/404071 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/404071/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-436 | Interpretation Conflict | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenClaw ClawScan | <= 0.1.6 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | New CVE Received | [email protected] |
| Sep 15, 2026 | CVE Modified | CISA-ADP |
Volerion