CVE-2026-18482 | Klarso Neo.mjs FileSystemService FileSystemService.mjs checkSyntax/runPlaywrightTest absolutePath os command injection (88c77fc4 / EUVD-2026-63326)
A vulnerability was found in Klarso Neo.mjs and classified as problematic. Affected by this vulnerability is the function checkSyntax/runPlaywrightTest of the file FileSystemService.mjs of the component FileSystemService. Executing a manipulation of the argument absolutePath can lead to os command injection.
This vulnerability is tracked as CVE-2026-18482. The attack can be launched remotely. No exploit exists.
Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More