Description
A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side request forgery
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an SSRF flaw exposed through the OpenClawConfigSync.buildBrowserConfig function in the Browser Network Configuration component. The flaw allows an attacker to manipulate the function’s input so that the server initiates HTTP requests to arbitrary internal or external resources, potentially exposing sensitive data, enabling further attacks, or causing unintended actions.

Affected Systems

Affected versions of netease‑youdao LobsterAI include 2026.6.15, 2026.8.28, 2026.9.3, and 2026.9.4. The impact applies to deployments where the Browser Network Configuration feature is enabled.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk, and with a publicly available exploit and no restriction on the attack vector, the vulnerability can be leveraged remotely. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the public availability of an exploit increases the likelihood of real‑world attacks.

Generated by OpenCVE AI on September 15, 2026 at 07:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update LobsterAI to a patched release that addresses SSRF in OpenClawConfigSync.buildBrowserConfig.
  • If patch is unavailable, restrict or disable the Browser Network Configuration feature to eliminate the vulnerable endpoint.
  • Monitor outbound traffic and logs for suspicious or unauthorized requests initiated by the application.

Generated by OpenCVE AI on September 15, 2026 at 07:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.
Title netease-youdao LobsterAI Browser Network Configuration openclawConfigSync.ts OpenClawConfigSync.buildBrowserConfig server-side request forgery
First Time appeared Netease-youdao
Netease-youdao lobsterai
Weaknesses CWE-918
CPEs cpe:2.3:a:netease-youdao:lobsterai:*:*:*:*:*:*:*:*
Vendors & Products Netease-youdao
Netease-youdao lobsterai
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Netease-youdao Lobsterai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T16:20:17.358Z

Reserved: 2026-09-13T18:43:42.987Z

Link: CVE-2026-90818

cve-icon Vulnrichment

Updated: 2026-09-16T16:20:13.703Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T21:17:41.987

Modified: 2026-09-16T17:18:17.783

Link: CVE-2026-90818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:45:15Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)