---
id: CVE-2026-90818
title: >-
  A security flaw has been discovered in netease-youdao LobsterAI
  2026.6.15/2026.8.28/2026.9.3/2026.9.4
summary: >-
  A security flaw has been discovered in netease-youdao LobsterAI
  2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function
  OpenClawConfigSync.buildBrowserConfig of the file
  src/main/libs/openclawConfigSync.ts of the component Browse…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: netease-youdao
product: LobsterAI
affected:
  - LobsterAI 2026.6.15
  - LobsterAI 2026.8.28
  - LobsterAI 2026.9.3
  - LobsterAI 2026.9.4
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T17:18:17.783'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90818'
references:
  - url: 'https://gist.github.com/YLChen-007/e5f88777e7c50549fd98b23b2988f78d'
    label: cna@vuldb.com
  - url: 'https://github.com/netease-youdao/LobsterAI/'
    label: cna@vuldb.com
  - url: 'https://github.com/netease-youdao/LobsterAI/issues/2181'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90818'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/922881'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403321'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403321/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00538
epssPercentile: 0.42805
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T16:20:06.645523Z'
ingestedAt: '2026-09-14T21:15:17.563Z'
---

## Overview

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
