CVE-2026-108156: LobsterAI 2026.5.27 through 2026.9.23 Arbitrary Directory Deletion via Skill _meta.json
LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects meta.json.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users running LobsterAI versions 2026.5.27 through 2026.9.23 are exposed if they install a crafted skill and later uninstall it. The impact is limited to directories writable by the affected user, but can include the user’s home directory.
What must an attacker do to exploit it?
An attacker must convince a user to install a malicious skill containing a crafted _meta.json file. The destructive deletion is triggered when the user uninstalls that skill.
Does the skill security scanner prevent exploitation?
No. The scanner does not inspect _meta.json, which allows the malicious openclawSourceDir value to pass through to the uninstall handler.