CVE-2026-90818: netease-youdao LobsterAI Browser Network Configuration openclawConfigSync.ts OpenClawConfigSync.buildBrowserConfig server-side request forgery
A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.
Affected Software
Event History
Frequently Asked Questions
Which LobsterAI releases are identified as affected?
The affected releases listed are 2026.6.15, 2026.8.28, 2026.9.3, and 2026.9.4.
What access does an attacker need to attempt exploitation?
The issue can be attacked remotely and the CVSS vector indicates no privileges are required. The same vector indicates user interaction is required.
Is exploit code publicly available?
Yes. The vulnerability information states that an exploit has been released publicly and may be used in attacks.