The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Cited CVE id is in the NVD or CISA KEV record.

1 caveat
  • ▲Specific CVE record and details not located in additional public sources searched.
Sourcing
1source

via NVD

NVD · track record
52Stories
100%Verified
2830d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw
VERIFIEDBy Xavier Rivera· ·1 min read

LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

Netease-youdao LobsterAI versions 2026.5.27 through 2026.9.23 contain CVE-2026-108156, a high-severity flaw that enables arbitrary directory deletion via a crafted skill's _meta.json file. The vulnerability carries a CVSS score of 7.1 and requires only that a user install the malicious skill.

Source:NVD
Post
LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

LobsterAI versions 2026.5.27 through 2026.9.23 contain a high-severity directory deletion vulnerability. The skills:delete handler trusts the openclawSourceDir value in a skill's _meta.json file, enabling recursive deletion of user-writable directories on uninstall. Attackers must first trick users into installing a malicious skill. This can affect home directories.

Netease-youdao LobsterAI versions 2026.5.27 through 2026.9.23 contain a high-severity vulnerability that can lead to arbitrary directory deletion.
This trust allows an attacker-supplied path to trigger recursive deletion of any user-writable directory.
The flaw resides in the skills deletion handler. CVE-2026-108156 affects the skills:delete IPC handler, which trusts the openclawSourceDir value stored in a skill's _meta.json file during uninstallation. This trust allows an attacker-supplied path to trigger recursive deletion of any user-writable directory.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Attackers must trick users into installing a crafted skill. The vulnerability requires user interaction to install the malicious skill. Once installed, uninstallation executes the deletion without further checks because the security scanner does not inspect _meta.json contents.
Successful exploitation can delete arbitrary directories, including the user's home directory, resulting in high integrity and availability effects with no confidentiality impact.
Impact reaches user home directories. The CVSS score of 7.1 places the issue in the high-severity category. Successful exploitation can delete arbitrary directories, including the user's home directory, resulting in high integrity and availability effects with no confidentiality impact.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
References point to the project repository and fix commit. The NVD record lists the LobsterAI GitHub repository, the specific handler code, a commit that addresses the issue, and an advisory from VulnCheck. The record was published on October 9, 2026.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilityai
More fromNVD
  • System Informer before 4.0.26241.138 exposed to local privilege escalation

    Tech · 51m
  • PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    Tech · 4h
  • Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Tech · 20h
More inTech
  • Modern Warfare 4 DMZ Early Access Opens October 20

    Tech · 3h
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 16h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 19h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    System Informer before 4.0.26241.138 exposed to local privilege escalation

    Winsiderss System Informer versions through 4.0.26241.138 contain an incorrect authorization flaw that lets local attackers execute code as SYSTEM from any signed process. Vulncheck rates the issue 7.8 and 8.5.

  • Tech· 

    PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    PHPNuxBill through 2025.3.20 is affected by CVE-2026-108108, a CVSS 7.1 authentication bypass in RADIUS CHAP verification. Attackers with a valid username can gain network access and consume customer plans using any password.

  • Tech· 

    IBM Security Verify Access: 4 more vulnerabilities disclosed

    IBM has disclosed four more flaws in Security Verify Access and Verify Identity Access, including a code execution bug it rates critical at 9.1 (NVD: 8.8). Versions 10.0 to 10.0.9.2 and 11.0 to 11.0.3 are affected. IBM says to upgrade to 10.0.9.3 or 11.0.3.1.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.