CVE-2026-27487

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, this created an OS command injection risk. This issue has been fixed in version 2026.2.14.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:27

Type Values Removed Values Added
Summary
  • (es) OpenClaw es un asistente personal de IA. En las versiones 2026.2.13 e inferiores, al usar macOS, la ruta de actualización de credenciales del llavero de Claude CLI construía un comando de shell para escribir el blob JSON actualizado en el Llavero a través de security add-generic-password -w .... Debido a que los tokens OAuth son datos controlados por el usuario, esto creaba un riesgo de inyección de comandos del sistema operativo. Este problema ha sido solucionado en la versión 2026.2.14.

23 Feb 2026, 20:41

Type Values Removed Values Added
First Time Openclaw openclaw
Apple macos
Apple
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
References () https://github.com/openclaw/openclaw/commit/66d7178f2d6f9d60abad35797f97f3e61389b70c - () https://github.com/openclaw/openclaw/commit/66d7178f2d6f9d60abad35797f97f3e61389b70c - Patch
References () https://github.com/openclaw/openclaw/commit/9dce3d8bf83f13c067bc3c32291643d2f1f10a06 - () https://github.com/openclaw/openclaw/commit/9dce3d8bf83f13c067bc3c32291643d2f1f10a06 - Patch
References () https://github.com/openclaw/openclaw/commit/b908388245764fb3586859f44d1dff5372b19caf - () https://github.com/openclaw/openclaw/commit/b908388245764fb3586859f44d1dff5372b19caf - Patch
References () https://github.com/openclaw/openclaw/pull/15924 - () https://github.com/openclaw/openclaw/pull/15924 - Issue Tracking
References () https://github.com/openclaw/openclaw/releases/tag/v2026.2.14 - () https://github.com/openclaw/openclaw/releases/tag/v2026.2.14 - Release Notes
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-4564-pvr2-qq4h - () https://github.com/openclaw/openclaw/security/advisories/GHSA-4564-pvr2-qq4h - Patch, Vendor Advisory

21 Feb 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-21 10:16

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27487

Mitre link : CVE-2026-27487

CVE.ORG link : CVE-2026-27487


JSON object : View

Products Affected

openclaw

  • openclaw

apple

  • macos
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')