SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90818

MEDIUM · CVSS 4.3 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the Browser Network Configuration component of netease-youdao LobsterAI allows for server-side request forgery, enabling remote attackers to manipulate server requests. Organizations using affected versions (2026.6.15, 2026.8.28, 2026.9.3, and 2026.9.4) should prioritize patching this flaw to mitigate potential exploitation, as the exploit has been publicly disclosed. Security teams must assess their exposure and implement necessary safeguards to protect against this medium-severity threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90818
Severity
MEDIUM
CVSS
4.3
EPSS
0.51%
GitHub

Original NVD Description

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.