Impact
The vulnerability is an SSRF flaw exposed through the OpenClawConfigSync.buildBrowserConfig function in the Browser Network Configuration component. The flaw allows an attacker to manipulate the function’s input so that the server initiates HTTP requests to arbitrary internal or external resources, potentially exposing sensitive data, enabling further attacks, or causing unintended actions.
Affected Systems
Affected versions of netease‑youdao LobsterAI include 2026.6.15, 2026.8.28, 2026.9.3, and 2026.9.4. The impact applies to deployments where the Browser Network Configuration feature is enabled.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and with a publicly available exploit and no restriction on the attack vector, the vulnerability can be leveraged remotely. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the public availability of an exploit increases the likelihood of real‑world attacks.
OpenCVE Enrichment