Command Injection Vulnerability in Neo.mjs FileSystemService Component by Neo Technologies
CVE-2026-18482

Currently unrated

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18482?

The Neo.mjs product contains a command injection vulnerability found in the FileSystemService.mjs component. This security flaw arises from the checkSyntax() and runPlaywrightTest() functions improperly interpolating absolute path values controlled by the caller into shell commands. This misconfiguration enables arbitrary OS command execution whenever an AI agent triggers these functions, making it a significant risk for users. The vulnerability has been addressed in commit 88c77fc, improving the security posture of the affected versions.

Affected Version(s)

neo-mjs 0 < 88c77fc4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.