Command Injection Vulnerability in Neo.mjs FileSystemService Component by Neo Technologies
CVE-2026-18482
Currently unrated
What is CVE-2026-18482?
The Neo.mjs product contains a command injection vulnerability found in the FileSystemService.mjs component. This security flaw arises from the checkSyntax() and runPlaywrightTest() functions improperly interpolating absolute path values controlled by the caller into shell commands. This misconfiguration enables arbitrary OS command execution whenever an AI agent triggers these functions, making it a significant risk for users. The vulnerability has been addressed in commit 88c77fc, improving the security posture of the affected versions.
Affected Version(s)
neo-mjs 0 < 88c77fc4
