CVE-2026-108156 | Netease-Youdao LobsterAI up to 2026.9.23 Skills Delete IPC _meta.json skills:delete IPC handler openclawSourceDir path traversal

SecurityVulns

A vulnerability was found in Netease-Youdao LobsterAI up to 2026.9.23. It has been rated as problematic. The impacted element is the function skills:delete IPC handler of the file _meta.json of the component Skills Delete IPC Handler. The manipulation of the argument openclawSourceDir leads to path traversal.

This vulnerability is documented as CVE-2026-108156. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More