Sceawere

Vulnerability Detail

CVE-2026-91836UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Incomplete Comparison in ClawScan

Vulnerability Metadata

Severity
Low
Score / CVSS
2.8
Creation Date
2h ago
Vendor
OpenClaw
Product
ClawScan
Attack Type
Incomplete Comparison with Missing Factors
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version 0.1.7 mitigates this issue. Patch name: 9f6a6fbb9f1137345566d0ab44c73893dfe112fa. The affected component should be upgraded.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.8",
  "pubDate": "2026-09-15T15:17:32.800Z",
  "pubdate": "2026-09-15T15:17:32.800Z",
  "executiveSummary": "OpenClaw ClawScan versions up to 0.1.6 are affected by an incomplete comparison vulnerability within the Static Scanner component.\nThe vulnerability resides in internal/runner/static_scanner.go and arises from a failure to account for all necessary factors during logical comparison operations.\nAn attacker with local access to the host can exploit this flaw to bypass intended security checks or influence scan results.\nThis vulnerability poses a significant risk to the integrity of the scanning process, potentially allowing for the omission of security findings or the misclassification of malicious artifacts.\nThe exploit for this vulnerability has been publicly disclosed, necessitating prompt remediation to prevent potential misuse.\nUsers are strongly advised to upgrade to version 0.1.7, which incorporates the necessary patches to address the logic error.",
  "technicalDetails": "The vulnerability is classified as an incomplete comparison, typically associated with improper validation of input parameters or internal state variables during conditional checks.\nIn the context of the Static Scanner component of OpenClaw ClawScan, specifically within the file internal/runner/static_scanner.go, the application performs comparative logic that fails to evaluate all relevant factors or conditions required for a secure security assessment.\nThe root cause of this issue stems from a flaw in the implementation of the comparison logic, where the scanner neglects to include critical contextual data or metadata during its analysis routine.\nBecause the logic fails to account for these 'missing factors,' the scanner can be influenced to produce incorrect output, potentially leading to false negatives during static analysis.\nExploitation is possible via the local host, meaning an attacker must have local access to the environment where ClawScan is executing. The exploit leverages this local execution context to manipulate the environment or the input data provided to the scanner.\nThe attack flow involves an attacker providing specifically crafted inputs or manipulating the environment in such a way that the incomplete comparison logic is triggered during the execution of the Static Scanner. By exploiting the logic gap, the attacker can cause the scanner to reach an incorrect conclusion, such as prematurely terminating a check or erroneously marking malicious code as benign.\nThe impact of a successful exploit is the bypass of security scanning mechanisms, which could allow malicious code or vulnerable patterns to persist undetected within an analyzed codebase.\nAs the exploit has been published, the barrier to entry for potential attackers is significantly lowered, increasing the probability of exploitation attempts against environments relying on the affected versions of ClawScan.\nThe vulnerability does not inherently require high-level privileges for the execution of the scanner itself, but the success of the exploitation is bounded by the local access requirements and the specific operational parameters set by the user or system administrator running the scan."
}
CVE-2026-91836: Incomplete Comparison in ClawScan (LOW Severity, CVSS: 2.8) | Sceawere