CVE-2026-91836: OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factors
A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/staticscanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version 0.1.7 mitigates this issue. Patch name: 9f6a6fbb9f1137345566d0ab44c73893dfe112fa. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClaw ClawScanto a version that resolves this vulnerability.Fixed in 0.1.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 9f6a6fbb9f1137345566d0ab44c73893dfe112fa
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to local-host attackers. The CVSS vector indicates that an attacker also needs low-level privileges and user interaction.
Which releases should be remediated?
OpenClaw ClawScan versions up to and including 0.1.6 are affected. Upgrade the Static Scanner component to version 0.1.7; the referenced patch is 9f6a6fbb9f1137345566d0ab44c73893dfe112fa.
Is exploitation theoretical?
No. An exploit has been published and may be used.