Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108156— LobsterAI 2026.5.27 through 2026.9.23 Arbitrary Directory Deletion via Skill _meta.json

Quick assessment

Affected
netease-youdao LobsterAI
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LobsterAI 2026.5.27 至 2026.9.23 版本中,在 IPC 处理程序里存在外部控制文件路径漏洞。该漏洞在卸载技能时,会信任技能 文件中的 值。攻击者通过诱导用户安装精心构造的技能,可在卸载过程中递归删除任意用户可写的目录(例如主目录),因为安全扫描器从未对 文件进行检查。

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1046 · Network Service Discovery

Affected Version Matrix 1

VendorProduct Version RangeStatus
netease-youdao LobsterAI 2026.5.27≤ 2026.9.23 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108156

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LobsterAI 2026.5.27 through 2026.9.23 Arbitrary Directory Deletion via Skill _meta.json
Source: CVE Program / CVE List V5
Vulnerability Description
LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
netease-youdao LobsterAI 2026.5.27 ~ 2026.9.23 -

II. Public POCs for CVE-2026-108156

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108156

请登录查看更多情报信息。

Other References for CVE-2026-108156 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-108156

No comments yet


Leave a comment