CVE Watcher
Sitemap Privacy Security.txt Open CVE Console

Shareable CVE page

CVE-2026-18482

This is the local share page for this CVE/source combination.

CVE-2026-18482

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.

low
SourceCVE List v5 CVSSn/a Severityunknown Published2026-08-20 EPSS0.8%
Open in CVE Console
Vector and technical detailsKlarso GmbH neo-mjs