← Back

CVE-2026-27487

nvd nist
Published: Feb 21, 2026Modified: Feb 23, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD

Description

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, this created an OS command injection risk. This issue has been fixed in version 2026.2.14.

Affected (1)

Products: Openclaw: Openclaw
1 product
Openclaw
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2026.2.14
Running on/withPlatform Versions
Apple
Macos
All versions

References (6)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
PatchVendor Advisory

Timeline

No history available yet.