VulnWatch VulnWatch
← Back to dashboard
Unknown nvd · CVE-2026-18482

CVE-2026-18482: Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-

Published Aug 20, 2026

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.

Affected AI Products

mcp server ai agent
Get the weekly digest. Every Monday: top AI security stories of the week. Free.