OS Command Injection in OpenClaw - CVE-2026-27487
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to command injection in the macOS keychain credential refresh path when writing user-controlled OAuth token data to Keychain via a shell command. A remote user can supply a specially crafted OAuth token value to execute arbitrary commands.
This issue affects macOS only and user interaction is required.