Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netease-youdao
Netease-youdao lobsterai |
|
| Vendors & Products |
Netease-youdao
Netease-youdao lobsterai |
Fri, 09 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json. | |
| Title | LobsterAI 2026.5.27 through 2026.9.23 Arbitrary Directory Deletion via Skill _meta.json | |
| Weaknesses | CWE-73 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T16:04:40.625Z
Reserved: 2026-10-09T15:41:44.132Z
Link: CVE-2026-108156
No data.
Status : Deferred
Published: 2026-10-09T17:16:46.540
Modified: 2026-10-09T17:41:47.060
Link: CVE-2026-108156
No data.
OpenCVE Enrichment
Updated: 2026-10-09T17:30:08Z
-
CWE-73
External Control of File Name or Path