---
id: CVE-2026-91836
title: A flaw has been found in OpenClaw ClawScan up to 0.1.6
summary: >-
  A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an
  unknown function of the file internal/runner/static_scanner.go of the
  component Static Scanner. This manipulation causes incomplete comparison with
  missing factors. …
severity: low
cvss: 2.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-1023
vendor: OpenClaw
product: ClawScan
affected:
  - ClawScan 0.1.0
  - ClawScan 0.1.1
  - ClawScan 0.1.2
  - ClawScan 0.1.3
  - ClawScan 0.1.4
  - ClawScan 0.1.5
  - ClawScan 0.1.6
published: '2026-09-15'
updated: '2026-09-20'
sourceUpdated: '2026-09-20T01:16:33.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91836'
references:
  - url: 'https://github.com/openclaw/clawscan/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/openclaw/clawscan/commit/9f6a6fbb9f1137345566d0ab44c73893dfe112fa
    label: cna@vuldb.com
  - url: 'https://github.com/openclaw/clawscan/issues/40'
    label: cna@vuldb.com
  - url: 'https://github.com/openclaw/clawscan/pull/41'
    label: cna@vuldb.com
  - url: 'https://github.com/openclaw/clawscan/releases/tag/v0.1.7'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-91836'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/933533'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/404072'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/404072/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-20T00:26:20.369742Z'
epss: 0.00325
epssPercentile: 0.22983
ingestedAt: '2026-09-15T15:39:12.902Z'
---

## Overview

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version 0.1.7 mitigates this issue. Patch name: 9f6a6fbb9f1137345566d0ab44c73893dfe112fa. The affected component should be upgraded.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
