Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Neo.mjs command injection in FileSystemService.mjs

Neo.mjs contains command injection vulnerabilities in the FileSystemService.mjs component where checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled paths into shell commands, enabling arbitrary OS command execution when AI agents invoke these tools.

Disclosed 20 August 2026 · Record updated 13 September 2026

Impact

Arbitrary OS command execution when AI agents are induced to invoke vulnerable tools through unsanitized path parameters

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18482