A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure | |
| First Time appeared |
Netease-youdao
Netease-youdao lobsterai |
|
| Weaknesses | CWE-200 CWE-284 |
|
| CPEs | cpe:2.3:a:netease-youdao:lobsterai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netease-youdao
Netease-youdao lobsterai |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-08-06T04:00:11.747Z
Updated: 2026-08-06T04:00:11.747Z
Reserved: 2026-08-05T19:31:06.424Z
Link: CVE-2026-18995
No data.
No data.
No data.