{"data":{"id":"25ca9ab2-dff6-47d8-b1b4-49f39feede0d","title":"CVE-2026-18482: Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-","summary":"Neo.mjs has a command injection vulnerability (a security flaw where attackers can run unauthorized operating system commands) in its FileSystemService.mjs component. The vulnerability exists in the checkSyntax() and runPlaywrightTest() functions, which unsafely insert user-provided file paths directly into shell commands, allowing an AI agent to execute arbitrary commands if tricked into using these tools.","solution":"Commit 88c77fc fixes these vulnerabilities.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18482","publishedAt":"2026-08-20T13:16:58.560Z","cveId":"CVE-2026-18482","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Neo.mjs"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-20T13:16:58.560Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}