LobsterAI 2026.5.27 至 2026.9.23 版本中,在 IPC 处理程序里存在外部控制文件路径漏洞。该漏洞在卸载技能时,会信任技能 文件中的 值。攻击者通过诱导用户安装精心构造的技能,可在卸载过程中递归删除任意用户可写的目录(例如主目录),因为安全扫描器从未对 文件进行检查。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| netease-youdao | LobsterAI | 2026.5.27≤ 2026.9.23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netease-youdao | LobsterAI | 2026.5.27 ~ 2026.9.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet