CyberRota Analysis
AI-GeneratedA vulnerability in the Browser Network Configuration component of netease-youdao LobsterAI allows for server-side request forgery, enabling remote attackers to manipulate server requests. Organizations using affected versions (2026.6.15, 2026.8.28, 2026.9.3, and 2026.9.4) should prioritize patching this flaw to mitigate potential exploitation, as the exploit has been publicly disclosed. Security teams must assess their exposure and implement necessary safeguards to protect against this medium-severity threat.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.