CRITICAL
Klarso GmbH
CVE published 2026-08-20
CVE-2026-18482
The CVE-2026-18482 vulnerability is a critical command injection issue within the FileSystemService.mjs component of the Neo.mjs library. This vulnerability, addressed by commit 88c77fc, allows for arbitrary OS command execution due to unsafe interpolation of caller-controlled absolutePath values into shell commands by the checkSyntax() and runPlaywrightTest() functions. Affected deployments should priori [truncated]