Neo.mjs 的 ai/mcp/server/file-system MCP 服务器中的 FileSystemService.mjs 组件存在命令注入漏洞。其中,checkSyntax() 和 runPlaywrightTest() 函数在不安全的情况下,将调用方控制的绝对路径(absolutePath)值直接拼接到 shell 命令中,从而导致在诱导 AI 代理调用这些工具时,可执行任意操作系统命令。提交 88c77fc 修复了这些漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Klarso GmbH | neo-mjs | < 88c77fc4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Klarso GmbH | neo-mjs | 0 ~ 88c77fc4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet