Neo.mjs command injection in FileSystemService.mjs
Neo.mjs contains command injection vulnerabilities in the FileSystemService.mjs component where checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled paths into shell commands, enabling arbitrary OS command execution when AI agents invoke these tools.
Disclosed 20 August 2026 · Record updated 13 September 2026
Impact
Arbitrary OS command execution when AI agents are induced to invoke vulnerable tools through unsanitized path parameters
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18482
