CVE-2026-108156

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets1 URL
Full discourse1 post
  • The Circuitry@thecircuitry_

    LobsterAI 2026.5.27–2026.9.23 hit by CVE-2026-108156 (CVSS 7.1). • Trusted openclawSourceDir in _meta.json • Uninstall deletes arbitrary user directories • Scanner skips the file entirely https://thecircuitry.to/article/lobsterai-versions-2026527-to-2026923-contain-high-severity-directory-deletion-f-mv1990gt https://t.co/Tgj1ec9DER

    0000026
    37 followersView on X

Explore more