CVE-2026-18482 PUBLISHED

CVE-2026-18482

Assigner: certcc
Reserved: 31.07.2026 Published: 20.08.2026 Updated: 20.08.2026

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.

Product Status

Vendor Klarso GmbH
Product neo-mjs
Versions
  • affected from 0 to 88c77fc4 (excl.)

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')