CVE-2026-108156
Deferred Deferred - Pending Action

Path Traversal in LobsterAI Skills Uninstall

Vulnerability report for CVE-2026-108156, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netease-youdao LobsterAI 2026.5.27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108156 is an external control of file path vulnerability in LobsterAI versions 2026.5.27 through 2026.9.23. It occurs in the skills:delete IPC handler where the application trusts the openclawSourceDir value from a skill's _meta.json file during uninstallation. Attackers can craft a skill with a malicious _meta.json file specifying a sensitive directory path. When uninstalled, the application recursively deletes that directory without validation.

Detection Guidance

Check LobsterAI installations for versions 2026.5.27 through 2026.9.23. Inspect _meta.json files in skill directories for an openclawSourceDir field pointing to sensitive paths. Look for unexpected directory deletions in system logs or user home directories.

Impact Analysis

This vulnerability allows attackers to delete arbitrary user-writable directories on your system, including critical folders like your home directory. If you install a malicious skill, the attacker could cause permanent data loss by deleting important files or directories. The attack requires user interaction to install the crafted skill.

Compliance Impact

This vulnerability could lead to unauthorized deletion of sensitive user data, potentially violating GDPR's data integrity and availability requirements (Article 5) and HIPAA's integrity and availability standards for protected health information. Unauthorized directory deletion may also constitute a breach of confidentiality if sensitive files are removed.

Mitigation Strategies

Upgrade LobsterAI to version 2026.9.24 or later. Remove the openclawSourceDir field from any _meta.json files in installed skills. Avoid installing untrusted skills until patched. Monitor for unusual file deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108156. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart