Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
CVE-2026-27487 is a high severity vulnerability with a CVSS score of 8.0. No known exploits currently, and patches are available.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
On macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, this created an OS command injection risk.
The fix avoids invoking a shell by using execFileSync("security", argv) and passing the updated keychain payload as a literal argument.
openclaw (npm)<= 2026.2.13>= 2026.2.14 (next release)main):
9dce3d8bf83f13c067bc3c32291643d2f1f10a0666d7178f2d6f9d60abad35797f97f3e61389b70cb908388245764fb3586859f44d1dff5372b19cafThanks @aether-ai-agent for reporting.
| Vendor | Product |
|---|---|
| Openclaw | Openclaw |
| Apple |
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.
| macOS |