<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>LobsterAI - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/lobsterai/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 17:25:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/lobsterai/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>LobsterAI Arbitrary File Deletion Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-lobsterai-arbitrary-deletion/</link><pubDate>Fri, 09 Oct 2026 17:25:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-lobsterai-arbitrary-deletion/</guid><description>LobsterAI versions 2026.5.27 through 2026.9.23 contain an arbitrary file deletion vulnerability in the skills:delete IPC handler, allowing attackers to delete arbitrary user-writable directories via malicious skill manifests.</description><content:encoded><![CDATA[<p>LobsterAI versions 2026.5.27 through 2026.9.23 are affected by an external control of file path vulnerability (CVE-2026-108156) within the skills:delete IPC handler. The vulnerability exists because the application trusts the 'openclawSourceDir' parameter defined in a skill's '_meta.json' file during the uninstallation process. An attacker can craft a malicious skill package with a manipulated 'openclawSourceDir' value. When a victim installs and subsequently uninstalls the malicious skill, the LobsterAI application performs a recursive deletion operation on the path specified in the configuration. Because the product's security scanner fails to validate the contents of '_meta.json', the application can be coerced into deleting sensitive, user-writable directories, including the user's home directory. This vulnerability poses a significant risk to data integrity for users of the LobsterAI platform.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in the unauthorized deletion of arbitrary directories and files within the scope of the user's permissions on the host system. This could lead to partial or complete loss of user data, disruption of system operations, and potential application instability. The scope of impact is limited to directories writable by the user running the LobsterAI application.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Update LobsterAI to a version later than 2026.9.23 immediately to address the vulnerability in the skills:delete IPC handler.</li>
<li>Audit existing installed skills for suspicious or unauthorized '_meta.json' files containing modified 'openclawSourceDir' parameters if the software cannot be patched immediately.</li>
<li>Implement file integrity monitoring (FIM) or access logging on sensitive user directories to detect recursive file deletion events initiated by the LobsterAI process.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>