What is CVE-2026-18995?
CVE-2026-18995 is an information disclosure flaw in the `parseMediaTokensFromText` function within the MEDIA Path Handler component of netease-youdao LobsterAI version 2026.6.10. This vulnerability can be exploited remotely, requiring immediate security updates.
Azərbaycanca: CVE-2026-18995, netease-youdao LobsterAI 2026.6.10 versiyasında MEDIA Path Handler komponentinin `parseMediaTokensFromText` funksiyasında informasiya sızmasına səbəb olan boşluqdur. Bu zəiflik uzaqdan hücuma imkan verir, sistem sahibləri təcili olaraq təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which version of netease-youdao LobsterAI is affected by CVE-2026-18995?
This vulnerability affects netease-youdao LobsterAI version 2026.6.10.
Where is CVE-2026-18995 located and how can it be exploited?
The vulnerability resides in the `parseMediaTokensFromText` function of the MEDIA Path Handler component and can be exploited remotely, leading to information disclosure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.