Junglewise Threat Intelligence

CVE-2026-18482: Neo.mjs command injection in FileSystemService MCP server

CVE-2026-18482 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Executive brief

Neo.mjs is a JavaScript framework that provides an AI agent interface to filesystem operations through a Model Context Protocol (MCP) server. The FileSystemService component unsafely executes shell commands with user-supplied file paths, allowing an AI agent to run arbitrary OS commands on the hosting system by requesting syntax checks or test execution on specially crafted filenames.

Technical details

The vulnerability is a command injection flaw in the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server. The checkSyntax() and runPlaywrightTest() functions interpolate caller-controlled absolutePath values directly into shell command strings instead of using safe parameter passing (argv arrays). Paths like "x.mjs; id" or "x.mjs && id" pass the containment validation function ensureSandboxed() (which only checks path containment) but are then executed through a shell, splitting at metacharacters and executing injected commands. The root cause is conflating two separate concerns: validating that a path is within a directory boundary (a lexical check) with validating that the path is safe to concatenate into a command. The fix uses execFile() with an argv array, where injection is structurally impossible, and canonicalizes path comparisons to prevent symlink-based escapes.

Affected products

  • Neo Neo.mjs <5acc564 (prior to fix)

Timeline

  • 2026-08-20: disclosed: CVE-2026-18482 published
  • 2026-07-24: patched: Fix 5acc564 merged (pass argv, not shell string)
  • 2026-08-11: patched: Fix 88c77fc merged (correct containment claims and remove misleading sandbox promise)

References