External risk intelligence

Neo.mjs MCP Server Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-18482

The vulnerability affects an MCP server component used for AI agent tool execution. While these services are typically deployed as backend utilities rather than public-facing edge gateways, the network-based attack vector allows for potential exposure if the server is improperly configured or accessible via an internal network reachable from the internet.

OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Neo.mjs, specifically a component within its AI agent server, has a critical vulnerability that allows for arbitrary operating system command execution. This occurs when an AI agent is tricked into using certain file system tools, potentially enabling unauthorized actions on affected systems. The main concern is confirming relevance and exposure to this type of AI agent interaction.

  • AI agent server can run any command.
  • Critical issue allows remote command execution.
  • Confirm exposure and relevance to AI agents.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking an AI agent into using specific file system tools. This would allow the attacker to inject and execute arbitrary operating system commands on the server, potentially leading to a complete compromise of the system.

  • No authentication or user interaction needed.
  • Invoking specific file system tools.
  • Arbitrary OS command execution.

Live Threat

Current exploitation, exposure, and threat context

When an AI agent invokes specific tools within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, attacker-controlled input could lead to arbitrary operating system command execution. This could affect the integrity and availability of the server's operating system.

  • OS commands and server system data.
  • AI agent invoked functions with crafted input.
  • Compromised server operating system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical command injection vulnerability in Neo.mjs impacts systems using its FileSystemService.mjs component for AI agent tool execution. Platform or infrastructure teams are likely responsible for managing this server, with vendor-management teams needing to coordinate any updates. The first practical step is to identify all instances of the affected server, confirm their accessibility and criticality, and then assign ownership for remediation.

  • Platform/Infrastructure teams own remediation.
  • Verify server reachability and criticality.
  • Plan and execute vendor-coordinated updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Neo.mjs and the FileSystemService component?

Neo.mjs is a web application framework that includes an MCP (Model Context Protocol) server. The FileSystemService.mjs component acts as a backend toolset, allowing AI agents to interact with and manage files on the host system as part of automated workflows.

How does CVE-2026-18482 trigger command injection?

This vulnerability is a form of OS Command Injection (CWE-78). It happens because the affected functions, checkSyntax() and runPlaywrightTest(), take file paths provided by an AI agent and insert them directly into system commands without proper sanitization. This allows malicious input to be executed as part of the command itself.

Do I need an AI agent to trigger this bug?

Yes. The vulnerability is specifically triggered when an AI agent is induced to invoke the vulnerable FileSystemService tools with crafted, malicious path inputs. It is not triggered by standard web browsing or routine requests that do not involve these specific AI-driven file system operations.

Is my server at risk according to Halo Surface Signal?

Halo Surface Signal indicates the risk is possible. While these MCP servers are typically backend utilities, they may be reachable if the service is misconfigured or accessible via an internal network that is exposed to the internet, potentially widening the attack surface.

How should I respond to the Neo.mjs vulnerability?

Begin by auditing your infrastructure to locate all instances of the ai/mcp/server/file-system component. Once identified, evaluate their network reachability and prioritize them for remediation. Coordinate with your team to apply the official vendor update, specifically ensuring you incorporate the fixes provided in commit 88c77fc.

References