Description
LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json.
Related CPE's
Could not find any relations
References
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
7.1 · High
Information
Source identifier
Vulnerability status
Deferred
Published
2026-10-09T17:16:46.540Z
3 hours agoLast modified
2026-10-09T17:41:47.060Z
2 hours ago