CVE-2026-91835
A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version 0.1.7 is sufficient to resolve this issue. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. You should upgrade the affected component.
Scoring
- Severity
- LOW
- CVSS base score
- 2.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.11%
- CWE
- CWE-436
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- OpenClaw ClawScan
- OpenClaw ClawScan
- OpenClaw ClawScan
- OpenClaw ClawScan
- OpenClaw ClawScan
- OpenClaw ClawScan
- OpenClaw ClawScan
- OpenClaw ClawScan
Weakness type
Related vulnerabilities
- CVE-2025-48384 — Git allows arbitrary code execution through broken config quoting
- CVE-2023-24813 — URI validation failure on SVG parsing. Bypass of CVE-2023-23924
- CVE-2025-25291 — ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
- CVE-2025-25292 — Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
- CVE-2022-36051 — Broken Authorization in ZITADEL Actions
- CVE-2023-36456 — Authentik lacks Proxy IP headers validation
- CVE-2022-35962 — Crafted link in Zulip message can cause disclosure of credentials
- CVE-2026-87627 — Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leve