CVE-2026-18995: netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure
A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18995?
CVE-2026-18995 has a medium severity rating of 4.3.
What type of vulnerability is CVE-2026-18995?
CVE-2026-18995 is classified as an information disclosure vulnerability.
How do I fix CVE-2026-18995?
To fix CVE-2026-18995, update to the latest version of netease-youdao LobsterAI that addresses this vulnerability.
Can CVE-2026-18995 be exploited remotely?
Yes, CVE-2026-18995 can be exploited remotely.
Which component is affected by CVE-2026-18995?
CVE-2026-18995 affects the MEDIA Path Handler within the artifactParser.ts file.