Description


LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json.

Related CPE's


Could not find any relations

Weaknesses



CWE-73

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

7.1 · High

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-09T17:16:46.540Z

3 hours ago

Last modified

2026-10-09T17:41:47.060Z

2 hours ago