Product
LobsterAI versions 2026.5.27 through 2026.9.23 contain an arbitrary file deletion vulnerability in the skills:delete IPC handler, allowing attackers to delete arbitrary user-writable directories via malicious skill manifests.