CVE-2026-18482: Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-
Summary
Neo.mjs has a command injection vulnerability (a security flaw where attackers can run unauthorized operating system commands) in its FileSystemService.mjs component. The vulnerability exists in the checkSyntax() and runPlaywrightTest() functions, which unsafely insert user-provided file paths directly into shell commands, allowing an AI agent to execute arbitrary commands if tricked into using these tools.
Solution / Mitigation
Commit 88c77fc fixes these vulnerabilities.
Vulnerability Details
EPSS: 0.0%
August 20, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18482
First tracked: August 20, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%