CVE-2026-27487

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, this created an OS command injection risk. This issue has been fixed in version 2026.2.14.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

23 Feb 2026, 20:41

Type Values Removed Values Added
First Time Openclaw openclaw
Apple macos
Apple
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
References () https://github.com/openclaw/openclaw/commit/66d7178f2d6f9d60abad35797f97f3e61389b70c - () https://github.com/openclaw/openclaw/commit/66d7178f2d6f9d60abad35797f97f3e61389b70c - Patch
References () https://github.com/openclaw/openclaw/commit/9dce3d8bf83f13c067bc3c32291643d2f1f10a06 - () https://github.com/openclaw/openclaw/commit/9dce3d8bf83f13c067bc3c32291643d2f1f10a06 - Patch
References () https://github.com/openclaw/openclaw/commit/b908388245764fb3586859f44d1dff5372b19caf - () https://github.com/openclaw/openclaw/commit/b908388245764fb3586859f44d1dff5372b19caf - Patch
References () https://github.com/openclaw/openclaw/pull/15924 - () https://github.com/openclaw/openclaw/pull/15924 - Issue Tracking
References () https://github.com/openclaw/openclaw/releases/tag/v2026.2.14 - () https://github.com/openclaw/openclaw/releases/tag/v2026.2.14 - Release Notes
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-4564-pvr2-qq4h - () https://github.com/openclaw/openclaw/security/advisories/GHSA-4564-pvr2-qq4h - Patch, Vendor Advisory

21 Feb 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-21 10:16

Updated : 2026-02-23 20:41


NVD link : CVE-2026-27487

Mitre link : CVE-2026-27487

CVE.ORG link : CVE-2026-27487


JSON object : View

Products Affected

openclaw

  • openclaw

apple

  • macos
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')