Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 13:16
Updated : 2026-09-03 17:42
NVD link : CVE-2026-18482
Mitre link : CVE-2026-18482
CVE.ORG link : CVE-2026-18482
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
