File Classifier Vulnerability in OpenClaw ClawScan by OpenClaw
CVE-2026-91835

2.4LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
15 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-91835?

A vulnerability in the File Classifier of OpenClaw ClawScan (versions up to 0.1.6) has been identified, specifically within the IsBinaryFile function located in internal/runner/static_scanner.go. This defect can lead to interpretation conflicts, requiring attackers to have local access to exploit it. The vulnerability has been publicly disclosed, highlighting the need for immediate patching. To mitigate this issue, users should upgrade to version 0.1.7, which includes a relevant fix (commit 04401337b3adb9343bd338b21e5e258bf49ca9c8) that addresses the problem.

Affected Version(s)

ClawScan 0.1.0

ClawScan 0.1.1

ClawScan 0.1.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

nedlir (VulDB User)
.