{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lobsterai/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lobsterai:lobsterai:2026.5.27:*:*:*:*:*:*:*","cpe:2.3:a:lobsterai:lobsterai:2026.9.23:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-108156"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LobsterAI (2026.5.27 through 2026.9.23)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LobsterAI"],"content_html":"\u003cp\u003eLobsterAI versions 2026.5.27 through 2026.9.23 are affected by an external control of file path vulnerability (CVE-2026-108156) within the skills:delete IPC handler. The vulnerability exists because the application trusts the 'openclawSourceDir' parameter defined in a skill's '_meta.json' file during the uninstallation process. An attacker can craft a malicious skill package with a manipulated 'openclawSourceDir' value. When a victim installs and subsequently uninstalls the malicious skill, the LobsterAI application performs a recursive deletion operation on the path specified in the configuration. Because the product's security scanner fails to validate the contents of '_meta.json', the application can be coerced into deleting sensitive, user-writable directories, including the user's home directory. This vulnerability poses a significant risk to data integrity for users of the LobsterAI platform.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in the unauthorized deletion of arbitrary directories and files within the scope of the user's permissions on the host system. This could lead to partial or complete loss of user data, disruption of system operations, and potential application instability. The scope of impact is limited to directories writable by the user running the LobsterAI application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate LobsterAI to a version later than 2026.9.23 immediately to address the vulnerability in the skills:delete IPC handler.\u003c/li\u003e\n\u003cli\u003eAudit existing installed skills for suspicious or unauthorized '_meta.json' files containing modified 'openclawSourceDir' parameters if the software cannot be patched immediately.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) or access logging on sensitive user directories to detect recursive file deletion events initiated by the LobsterAI process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T17:25:58Z","date_published":"2026-10-09T17:25:58Z","id":"https://feed.craftedsignal.io/briefs/2026-10-lobsterai-arbitrary-deletion/","summary":"LobsterAI versions 2026.5.27 through 2026.9.23 contain an arbitrary file deletion vulnerability in the skills:delete IPC handler, allowing attackers to delete arbitrary user-writable directories via malicious skill manifests.","title":"LobsterAI Arbitrary File Deletion Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-lobsterai-arbitrary-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - LobsterAI","version":"https://jsonfeed.org/version/1.1"}