Junglewise Threat Intelligence

CVE-2026-90818: Netease Youdao LobsterAI server-side request forgery in browser configuration

CVE-2026-90818 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Executive brief

LobsterAI is an open-source desktop AI agent that automates tasks like data analysis and web research. A server-side request forgery (SSRF) vulnerability in the browser network configuration component allows remote attackers to make the application send unauthorized requests to internal or external systems, potentially exposing internal services or data.

Technical details

The vulnerability exists in the OpenClawConfigSync.buildBrowserConfig function within the browser network configuration component (src/main/libs/openclawConfigSync.ts). This is a server-side request forgery (SSRF) flaw where user-supplied input is not properly validated before being used in network requests. The vulnerability can be exploited remotely without authentication. An attacker can leverage this to access internal services, perform actions on behalf of the application, or redirect requests to attacker-controlled servers. Public exploit code has been released.

Affected products

  • Netease Youdao LobsterAI 2026.6.15, 2026.8.28, 2026.9.3, 2026.9.4

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: exploited: Public exploit code released

References