CVE-2026-27487
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, this created an OS command injection risk. This issue has been fixed in version 2026.2.14.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/openclaw/openclaw/releases/tag/v2026.2.14, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27487.json, https://github.com/openclaw/openclaw/security/advisories/GHSA-4564-pvr2-qq4h, https://nvd.nist.gov/vuln/detail/CVE-2026-27487, https://github.com/openclaw/openclaw/commit/66d7178f2d6f9d60abad35797f97f3e61389b70c, https://github.com/openclaw/openclaw/commit/9dce3d8bf83f13c067bc3c32291643d2f1f10a06, https://github.com/openclaw/openclaw/commit/b908388245764fb3586859f44d1dff5372b19caf, https://github.com/openclaw/openclaw/pull/15924
