VYPR

neo

by Neomjs

Source repositories

CVEs (1)

  • CVE-2026-18482Aug 20, 2026
    risk 0.00cvss epss

    Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands,…