๐Ÿ” CVE Alert

CVE-2026-18482

UNKNOWN 0.0

CVE-2026-18482

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.

Vendor klarso gmbh
Product neo-mjs
Published Aug 20, 2026
Last Updated Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for klarso gmbh neo-mjs

Be the first to know when new unknown vulnerabilities affecting klarso gmbh neo-mjs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Klarso GmbH / neo-mjs
0 < 88c77fc4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/neomjs/neo/commit/5acc564ea1b278bca5fab1f8f397a6ba9b849d75 novice-22.com: https://novice-22.com/posts/cve-2026-18482-neo.mjs/ github.com: https://github.com/neomjs/neo/commit/88c77fc4