CVE-2026-91835
Received Received - Intake

Interpretation Conflict in OpenClaw ClawScan File Classifier

Vulnerability report for CVE-2026-91835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulDB

Description

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version 0.1.7 is sufficient to resolve this issue. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
openclaw clawscan to 0.1.7 (exc)
openclaw clawscan 0.1.7
openclaw clawscan to 0.1.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-436 Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in OpenClaw ClawScan versions up to 0.1.6. It is located in the IsBinaryFile function within the internal/runner/static_scanner.go file, specifically in the File Classifier component. The issue involves interpretation conflict, meaning the system may misinterpret file types or content. Exploitation requires local access to the system.

Detection Guidance

Detection requires local access to the system. Check the version of OpenClaw ClawScan installed. If it is version 0.1.6 or earlier, the system is vulnerable. Use commands like 'clawscan --version' or inspect the file internal/runner/static_scanner.go for the IsBinaryFile function.

Impact Analysis

The vulnerability could allow an attacker with local access to manipulate file classification, potentially leading to incorrect handling of files. This might cause unintended behavior in the application, such as misclassifying binary files or executing unintended operations. However, the impact is limited due to the requirement for local access and the low CVSS scores.

Compliance Impact

This vulnerability allows malicious scripts to bypass static security scans by prepending a null byte, potentially evading detection of harmful content. For compliance like GDPR or HIPAA, which require thorough security scanning and risk assessment, this bypass could lead to undetected vulnerabilities or malware in systems, violating data protection and security requirements.

Mitigation Strategies

Upgrade OpenClaw ClawScan to version 0.1.7 or later. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. This resolves the issue by addressing the interpretation conflict in the IsBinaryFile function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart