{"id":"CVE-2026-18482","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-18482","summary":"CVE-2026-18482","details":"Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.","published":"2026-08-20T12:36:40.567Z","modified":"2026-08-22T03:51:40.940520126Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/neomjs/neo/commit/5acc564ea1b278bca5fab1f8f397a6ba9b849d75","label":"neomjs/neo@5acc564"},"references":[{"type":"WEB","url":"https://novice-22.com/posts/neo-mjs/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18482.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18482"},{"type":"FIX","url":"https://github.com/neomjs/neo/commit/5acc564ea1b278bca5fab1f8f397a6ba9b849d75"},{"type":"FIX","url":"https://github.com/neomjs/neo/commit/88c77fc4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-22T03:51:40.940520126Z"}}